Graylog2Splunk question

When I forward logs to splunk neith multiple streams to the same port they are all under the same sourcetype.

Is there a way to change this? There really isn’t much of a way to differentiate between the logs by host, sourcetype or source.

Thank you.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.