I believe your use case is related to the following Docs, it has detailed instructions how to override the sourcetypes. This should be configured on Heavy Forwarder in your case. It requires a splunkd restart on HF and the change applies to new events only after restart. https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.4/configure-source-types/override-source-types-on-a-per-event-basis
... View more