z/OS SYSLOG from ARCHIVE data stream

This reference lists the configuration values that you can update in the Configure data stream window for the z/OS SYSLOG from ARCHIVE data stream.

Configuration values that you can update

Name
The name that uniquely identifies the data stream to the Configuration Tool. If you want to add more data streams of the same type, you must first rename the last stream that you added.
Data Source Name
The name that uniquely identifies the data source to subscribers.
Tip: If you use the Auto-Qualify field in the subscriber configuration to fully qualify the data source name, this dataSourceName value is automatically updated with the fully qualified data source name. For more information about the values that you can select in the Auto-Qualify field, see Subscriber configuration.
File Path
A unique identifier that represents the data origin. For the z/OS SYSLOG from ARCHIVE data stream, the identifier should not be a real file path. The file path is used as a key to configure archived z/OS® SYSLOG data sets to collect in the Log Forwarder batch job. For more information, see Customizing the Log Forwarder batch job to send SYSLOG data to the Data Streamer. The Log Forwarder link these data sets with corresponding data origin.

The default value for this field is Data Source Type_Data Source Name.

Customized Data Source Type
A specification of whether to customize the data source type for Splunk HEC. The default value is No, which represents that the subscriber uses the default data source type to identify the type and format of the streamed data. If the value is set to Yes, you need to specify the data source type for Splunk HEC in the following Data Source Type for Splunk HEC field.
Data Source Type for Splunk HEC
A value that the subscriber can use to uniquely identify the type and format of the streamed data. This field is available only when you set the value of Customized Data Source Type to Yes, choose to customize the data source type and the protocol is Splunk HEC with customized field support or Splunk HEC with customized field support secure. The default value is Data Source Type_KV. You can specify the value according to your needs.