Getting Data In

Is it possible to label somehow the log being forwarded? We use the same sourcetype for a bunch of logs on the same machine.

Explorer

By default in this situation Splunk adds a suffix to the sourcetype in the main Splunk (the receiver) such as
some_sourcetype
some_sourcetype-2
some_sourcetype-3
...
But it would be really helpful either to create a label for the forwarded log or get the log name itself with a full path (same thing that goes into [monitor://...] in inputs.conf).
Please let me know if there is a way.

I am using Universal Forwarder on Linux.

Thanks a lot!

Tags (1)
0 Karma

Legend

Umm, have you seen the source field?

Explorer

🙂
Somehow I misunderstood it in the manual for inputs.conf.
Thanks again!

0 Karma