By default in this situation Splunk adds a suffix to the sourcetype in the main Splunk (the receiver) such as
some_sourcetype
some_sourcetype-2
some_sourcetype-3
...
But it would be really helpful either to create a label for the forwarded log or get the log name itself with a full path (same thing that goes into [monitor://...] in inputs.conf).
Please let me know if there is a way.
I am using Universal Forwarder on Linux.
Thanks a lot!
Umm, have you seen the source field?
🙂
Somehow I misunderstood it in the manual for inputs.conf.
Thanks again!