How do I change the sourcetype for evenets from Windows eventlog, it is usualy WinEventLog:
[WinEventLog:System]
sourcetype=tidal_evtl
disabled = 0
the events arrive with a sourcetype of WinEventLog:System instead of tidal_evtl.
Using the props.conf file on the indexer might be the way to go. The following should make everything with a source of WinEventLog:System have a sourcetype of tidal_evtl.
[source::WinEventLog:System]
sourcetype = tidal_evtl
Well this will not solve my problem, I have to assign different source types to the same event log on different servers, so I have to change it on the forwarder, not on the indexer.
I know not the proper way to do it in Splunk, but his is an app I inherited which relays on this.