Supported Data Types:
π Logs | π Metrics | π¦ TracesConfiguration
Splunk HEC Destination Configuration
Advanced Options
Setting Source and Source Type
By default, sources like Fluent Forward do not set Splunksource and sourcetype. You can set fallback values for all events through the Source and Source Type destination options above.
To set them dynamically per-event, use a Modify Attribute Processor to set Resource.com\.splunk\.source and Resource.com\.splunk\.sourcetype β either to a static value or from an existing log attribute. When present, these resource attributes override the static destination values.