Is it possible to change Haproxy add-on to recognize sourcetype other than haproxy:default(tcp(http)? If so, where can I do it in Splunk cloud. Thanks
You can always change the sourcetype for data, but it is NOT retroactive. Only new data will be affected. You cannot change the sourcetype of data that has already been indexed.