I have a syslog server and all the syslogs are currently going to KiwiSyslog. I have the Splunk Enterprise addition and would like to get data from KiwiSyslog server. I have already installed Splunk Universal Forwarder and I can see the data in the Splunk.
The question is how can I change the sourcetype or sourcename and call it instead of source="F:\Syslog\Cisco\Switches\xyz.log to something like _sourcetype="CISCO_SWITCHES"
Please advise!
Thanks,