<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change the syslog sourcetype in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Change-the-syslog-sourcetype/m-p/56430#M738</link>
    <description>&lt;P&gt;Yep it worked.. Thanks for that...&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2012 06:05:52 GMT</pubDate>
    <dc:creator>KarunK</dc:creator>
    <dc:date>2012-01-24T06:05:52Z</dc:date>
    <item>
      <title>Change the syslog sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Change-the-syslog-sourcetype/m-p/56428#M736</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I need to change the source-type "syslog" to "abc_syslog". My understanding is we cannot change the source-type once the log is indexing.&lt;/P&gt;

&lt;P&gt;Any suggestions please ?&lt;/P&gt;

&lt;P&gt;input.conf file at the forwader is given below. I tried to add the sourcetype at the forwarder as "abc_syslog" in the input.conf file (below), but the splunk even stopped indexing.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/adm/messages]
host = ssapp0813
index = abc_syslog
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 24 Jan 2012 01:41:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Change-the-syslog-sourcetype/m-p/56428#M736</guid>
      <dc:creator>KarunK</dc:creator>
      <dc:date>2012-01-24T01:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: Change the syslog sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Change-the-syslog-sourcetype/m-p/56429#M737</link>
      <description>&lt;P&gt;Judging by the example given, you changed the index, not the sourcetype.&lt;/P&gt;

&lt;P&gt;If you're wanting to change all the sourcetypes from the source /var/adm/messages, you can do the following:&lt;/P&gt;

&lt;P&gt;On the indexer, add the following to $SPLUNK_HOME/etc/system/local/props.conf&lt;/P&gt;

&lt;P&gt;[source::/var/adm/messages]&lt;/P&gt;

&lt;P&gt;sourcetype=abc_syslog&lt;/P&gt;

&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 03:02:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Change-the-syslog-sourcetype/m-p/56429#M737</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2012-01-24T03:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Change the syslog sourcetype</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Change-the-syslog-sourcetype/m-p/56430#M738</link>
      <description>&lt;P&gt;Yep it worked.. Thanks for that...&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 06:05:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Change-the-syslog-sourcetype/m-p/56430#M738</guid>
      <dc:creator>KarunK</dc:creator>
      <dc:date>2012-01-24T06:05:52Z</dc:date>
    </item>
  </channel>
</rss>

