I switched to SplunkForwarder (for other reasons). This solution does work for SplunkForwarder. It seems like kind of a big hammer to use on this nail, but in my case it's a satisfactory solution. Thank you very much.
... View more
The sourcetype might be getting set elsewhere in a file/location that takes precedence. If it were me, I'd:
find /opt/splunk/etc -name "*.conf" -exec grep -l snort {} \;
to look for possible candidates.
... View more