Hi @ITSplunk117 , yes it's possible to override the original sourcetype value with a new one using the procedure at https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Advancedsourcetypeov...
See more...
Hi @ITSplunk117 , yes it's possible to override the original sourcetype value with a new one using the procedure at https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Advancedsourcetypeoverrides Only one attention pont: sourcetype overriding, as all transformations, must be performed on the first full Splunk instance that data re passing through, not necessarily on the Indexers. In other words, if you have one or more intermediate heavy Forwarders, you must locate the transformation in the first Heavy Forwarder, not on the Indexers, because transformations are applied on the first Heavy Forwarder. Ciao. Giuseppe