Getting Data In

Is it possible to label somehow the log being forwarded? We use the same sourcetype for a bunch of logs on the same machine.

yg
Explorer

By default in this situation Splunk adds a suffix to the sourcetype in the main Splunk (the receiver) such as
some_sourcetype
some_sourcetype-2
some_sourcetype-3
...
But it would be really helpful either to create a label for the forwarded log or get the log name itself with a full path (same thing that goes into [monitor://...] in inputs.conf).
Please let me know if there is a way.

I am using Universal Forwarder on Linux.

Thanks a lot!

Tags (1)
0 Karma

Ayn
Legend

Umm, have you seen the source field?

yg
Explorer

🙂
Somehow I misunderstood it in the manual for inputs.conf.
Thanks again!

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...