Getting Data In

Is it possible to label somehow the log being forwarded? We use the same sourcetype for a bunch of logs on the same machine.

yg
Explorer

By default in this situation Splunk adds a suffix to the sourcetype in the main Splunk (the receiver) such as
some_sourcetype
some_sourcetype-2
some_sourcetype-3
...
But it would be really helpful either to create a label for the forwarded log or get the log name itself with a full path (same thing that goes into [monitor://...] in inputs.conf).
Please let me know if there is a way.

I am using Universal Forwarder on Linux.

Thanks a lot!

Tags (1)
0 Karma

Ayn
Legend

Umm, have you seen the source field?

yg
Explorer

🙂
Somehow I misunderstood it in the manual for inputs.conf.
Thanks again!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...