Getting Data In

Is it possible to label somehow the log being forwarded? We use the same sourcetype for a bunch of logs on the same machine.


By default in this situation Splunk adds a suffix to the sourcetype in the main Splunk (the receiver) such as
But it would be really helpful either to create a label for the forwarded log or get the log name itself with a full path (same thing that goes into [monitor://...] in inputs.conf).
Please let me know if there is a way.

I am using Universal Forwarder on Linux.

Thanks a lot!

Tags (1)
0 Karma


Umm, have you seen the source field?


Somehow I misunderstood it in the manual for inputs.conf.
Thanks again!

0 Karma