if you are using this app splunk-for-juniper-sa then you should use juniper_sa_log
but it should automatically as per props.conf:
[source::udp:514]
TRANSFORMS-sasourcetype= sa_sourcetyper
and transforms.conf:
[sa_sourcetyper]
DEST_KEY = MetaData:Sourcetype
REGEX = Juniper\:\s[^\s]+\s[^\s]+\s-\sive
FORMAT = sourcetype::juniper_sa_log
Thanks, started to work after adding those lines to props.conf. Also had to modify regex to Juniper:\s[^\s]+\s[^\s]+\s-\s