Yes, it is possible. Note, it may cause excessive CPU usage on the indexer / heavy forwarder. props.conf and transforms.conf (most likely on indexer, but if you have the data coming to a heavy forwarder, then put the props and transforms there as well) In the transforms example below, adjust the regex to grab the field you are looking for. For More details, see: https://docs.splunk.com/Documentation/Splunk/8.0.4/Data/Advancedsourcetypeoverrides props.conf [<sourcetype>] TRANSFORMS-changedatasource = datasource_finder transforms.conf [datasource_finder] SOURCE_KEY = _raw REGEX = datasource=(\w+) DEST_KEY = MetaData:Sourcetype FORMAT = sourcetype::$1
... View more