Getting Data In

Is it possible to label somehow the log being forwarded? We use the same sourcetype for a bunch of logs on the same machine.

yg
Explorer

By default in this situation Splunk adds a suffix to the sourcetype in the main Splunk (the receiver) such as
some_sourcetype
some_sourcetype-2
some_sourcetype-3
...
But it would be really helpful either to create a label for the forwarded log or get the log name itself with a full path (same thing that goes into [monitor://...] in inputs.conf).
Please let me know if there is a way.

I am using Universal Forwarder on Linux.

Thanks a lot!

Tags (1)
0 Karma

Ayn
Legend

Umm, have you seen the source field?

yg
Explorer

🙂
Somehow I misunderstood it in the manual for inputs.conf.
Thanks again!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...