I do not have personal experience with this, but I did find this on Splunkbase:
Important: If you are forwarding data, and you want to assign a source type for a source, you must do this in props.conf on the forwarder. If you do it in props.conf on the receiver, the override will not take effect.
To override source type assignment, add a stanza for your source to props.conf. In the stanza, identify the source path, using regex syntax for flexibility if necessary. Then specify the source type by including a sourcetype attribute
from:
http://docs.splunk.com/Documentation/Splunk/latest/Data/Bypassautomaticsourcetypeassignment
So I think for the deafult InterMapper install (UDP, port 514) , adding the following to the forwarder props.conf would work. If you are using 514 for other logs, you could set InterMapper to a different UDP port and match the change in the props.conf
[source::udp:514]
sourcetype=InterMapper
Let me know if that helps and I will update our documentation and testing scenarios.
Thanks for your interest.
Gurdev
... View more