If you want to override a source type, you must configure the setting in props.conf on the forwarder where the input is configured. To override source type assignment, add a stanza for your source to props.conf . In the stanza, identify the source path, using regular expression (regex) syntax for flexibility if necessary. Then specify the source type by including a sourcetype attribute. For example: [source::.../var/log/abc.log(.\d+)?] sourcetype=abc https://docs.splunk.com/Documentation/Splunk/8.0.6/Data/Bypassautomaticsourcetypeassignment ----------------------------------------------------------- If this helps, your like will be appreciated. 😊
... View more