<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does Splunk Add-on for Cisco ASA change the sourcetype for those logs then on and can it change the sourcetype for logs already indexed? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Splunk-Add-on-for-Cisco-ASA-change-the-sourcetype-for-those/m-p/164528#M15513</link>
    <description>&lt;P&gt;When you install the Splunk add-on for Cisco ASA does it change the sourcetype for those logs going forward? Also, can it change the sourcetype for logs already indexed?&lt;/P&gt;</description>
    <pubDate>Wed, 15 Oct 2014 19:52:13 GMT</pubDate>
    <dc:creator>lancasterad</dc:creator>
    <dc:date>2014-10-15T19:52:13Z</dc:date>
    <item>
      <title>Does Splunk Add-on for Cisco ASA change the sourcetype for those logs then on and can it change the sourcetype for logs already indexed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Splunk-Add-on-for-Cisco-ASA-change-the-sourcetype-for-those/m-p/164528#M15513</link>
      <description>&lt;P&gt;When you install the Splunk add-on for Cisco ASA does it change the sourcetype for those logs going forward? Also, can it change the sourcetype for logs already indexed?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2014 19:52:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Splunk-Add-on-for-Cisco-ASA-change-the-sourcetype-for-those/m-p/164528#M15513</guid>
      <dc:creator>lancasterad</dc:creator>
      <dc:date>2014-10-15T19:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk Add-on for Cisco ASA change the sourcetype for those logs then on and can it change the sourcetype for logs already indexed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Splunk-Add-on-for-Cisco-ASA-change-the-sourcetype-for-those/m-p/164529#M15514</link>
      <description>&lt;P&gt;If I remember correctly, the props.conf file included with this app uses the "rename=" function. This is a search-time rename so if you have a sourcetype named "foo" and you created this stanza:&lt;/P&gt;

&lt;P&gt;[foo]&lt;BR /&gt;
rename = bar&lt;/P&gt;

&lt;P&gt;From now on, you could search "sourcetype=bar" for ALL data indexed of the original sourcetype "foo" because it is a search-time transformation. The original sourcetype should be available in _sourcetype.&lt;/P&gt;

&lt;P&gt;You can reference this doc: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Admin/Propsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Admin/Propsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2014 20:47:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Splunk-Add-on-for-Cisco-ASA-change-the-sourcetype-for-those/m-p/164529#M15514</guid>
      <dc:creator>jlanders</dc:creator>
      <dc:date>2014-10-15T20:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk Add-on for Cisco ASA change the sourcetype for those logs then on and can it change the sourcetype for logs already indexed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Splunk-Add-on-for-Cisco-ASA-change-the-sourcetype-for-those/m-p/164530#M15515</link>
      <description>&lt;P&gt;I don't find that rename clause in the app.&lt;/P&gt;

&lt;P&gt;$ pwd&lt;BR /&gt;
/home/jimd/splunkTAasa/Splunk_TA_cisco-asa/default&lt;BR /&gt;
$ grep -i rename props.conf&lt;BR /&gt;
$&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:16:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Does-Splunk-Add-on-for-Cisco-ASA-change-the-sourcetype-for-those/m-p/164530#M15515</guid>
      <dc:creator>JimDeich</dc:creator>
      <dc:date>2020-09-28T19:16:53Z</dc:date>
    </item>
  </channel>
</rss>

