We're using Syslog-ng in our environment and have a forwarder setup on syslog-ng to forward the logs to Splunk. But when they're indexed in Splunk, the sourcetype is "syslog". Is it possible to set this to the actual source type? For example our syslog-ng directory structure looks like such:
I want to be able to set log-type to be the sourcetype in Splunk. It has to be possible!
asked 06 Apr '12, 08:59
You would have to set up different monitor stanzas in
If you do not specify sourcetype (which I assume you have not done) Splunk will probably identify and classify it as
Therefore you will also have to set the
Hope this helps,
answered 06 Apr '12, 09:17