The universal forwarder has a very simple configuration of what to scan for (inputs.conf) and where to send it to (outputs.conf).
Splunk indexer has the following in props.conf
sourcetype = log4j
I want every *.log4j file to have "log4j" sourcetype but it doesn't work when receiving information from the forwarder.
For example, I see the following from "summary" screen in indexer:
How can I have "app.log.2011-04-04.log4j" to be assigned "log4j" sourcetype?
You need to put that [source::.../....log4j] stanza on the forwarder, where it will be set on the input. Please see: http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F
View solution in original post