When I forward logs to splunk neith multiple streams to the same port they are all under the same sourcetype.
Is there a way to change this? There really isn’t much of a way to differentiate between the logs by host, sourcetype or source.
Thank you.