<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I change _internal index sourcetype? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397439#M70852</link>
    <description>&lt;P&gt;There are number of sourcetypes that are present in _internal index [ all of them related core splunk]. Which sourcetype has changed and what's the change?&lt;/P&gt;</description>
    <pubDate>Tue, 26 Feb 2019 09:26:55 GMT</pubDate>
    <dc:creator>lakshman239</dc:creator>
    <dc:date>2019-02-26T09:26:55Z</dc:date>
    <item>
      <title>How do I change _internal index sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397437#M70850</link>
      <description>&lt;P&gt;Some how the _internal index changed its sourcetype. How does one go about changing it back? I am not to worried about the data that has already been indexed, but I need to make sure any new data is under the correct sourcetype.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 20:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397437#M70850</guid>
      <dc:creator>wralph_EPACN</dc:creator>
      <dc:date>2019-02-25T20:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change _internal index sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397438#M70851</link>
      <description>&lt;P&gt;What do you mean by the index changing its sourcetype?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 08:21:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397438#M70851</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-02-26T08:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change _internal index sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397439#M70852</link>
      <description>&lt;P&gt;There are number of sourcetypes that are present in _internal index [ all of them related core splunk]. Which sourcetype has changed and what's the change?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 09:26:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397439#M70852</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-02-26T09:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change _internal index sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397440#M70853</link>
      <description>&lt;P&gt;Nothing has changed. Internal index contains several sourcetypes, and you just need to search for the one you're looking for&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 10:56:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397440#M70853</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2019-02-26T10:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change _internal index sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397441#M70854</link>
      <description>&lt;P&gt;This is part of the search I am doing, &lt;STRONG&gt;index=_internal source=&lt;EM&gt;license_usage.log type="Usage" splunk_server=&lt;/EM&gt; earliest=-7d@d latest=@d&lt;/STRONG&gt;. Some how the source type changed from splunkd to cisco:ios and I am wondering how this happened and how to change it back. As this report runs once a week I did not catch it till this past run where it failed to produce anything.&lt;/P&gt;

&lt;P&gt;So the question could possibly be stated, how do i change the the licence_usage.log, and whatever else that uses splunkd as a sourcetype back to its default?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:26:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397441#M70854</guid>
      <dc:creator>wralph_EPACN</dc:creator>
      <dc:date>2020-09-29T23:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change _internal index sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397442#M70855</link>
      <description>&lt;P&gt;Run &lt;CODE&gt;/opt/splunk/bin/splunk btool inputs list --debug | grep /var/log/splunk/ -B 10 -A 10&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Check if these inputs are having a sourcetype different than normal being assigned.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 13:56:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397442#M70855</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2019-02-26T13:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change _internal index sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397443#M70856</link>
      <description>&lt;P&gt;Given the sourcetype assigned, check the add-on related to cisco:ios and check for any faulty sourcetype overrides there.&lt;/P&gt;

&lt;P&gt;Or in general, do a: &lt;CODE&gt;/opt/splunk/bin/splunk btool props list --debug | grep "cisco:ios" -B 10 -A 10&lt;/CODE&gt; and &lt;CODE&gt;/opt/splunk/bin/splunk btool transforms list --debug | grep "cisco:ios" -B 10 -A 10&lt;/CODE&gt; to find any props or transforms related to setting that sourcetype.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 14:03:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397443#M70856</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-02-26T14:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change _internal index sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397444#M70857</link>
      <description>&lt;P&gt;I checked this against my prod environment and it besides for the host name everything was the same.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 14:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397444#M70857</guid>
      <dc:creator>wralph_EPACN</dc:creator>
      <dc:date>2019-02-26T14:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change _internal index sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397445#M70858</link>
      <description>&lt;P&gt;both look fine to me, but this is the first time i am trying to debug an app so...&lt;BR /&gt;
the first command i get:&lt;BR /&gt;
&lt;EM&gt;/opt/splunk/etc/system/default/props.conf                                 SHOULD_LINEMERGE = false&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 TRANSFORMS =&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 TRUNCATE = 10000&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 category = Network &amp;amp; Security&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 description = Output produced by the Cisco Adaptive Security Appliance (ASA) Firewall&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 detect_trailing_nulls = false&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 maxDist = 100&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 priority =&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 pulldown_type = 1&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 sourcetype =&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/props.conf                      [cisco:ios]&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 ADD_EXTRA_TIME_FIELDS = True&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 ANNOTATE_PUNCT = True&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 AUTO_KV_JSON = true&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 BREAK_ONLY_BEFORE =&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 BREAK_ONLY_BEFORE_DATE = True&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 CHARSET = UTF-8&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 DATETIME_CONFIG = /etc/datetime.xml&lt;BR /&gt;
/opt/splunk/etc/system/default/props.conf                                 DEPTH_LIMIT = 1000&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/props.conf                      EVAL-app = "cisco:ios"&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/props.conf                      EVAL-authenticator = coalesce(authenticator, case(facility == "PEM" AND mnemonic == "WEBAUTHFAIL", "webauth", facility == "DOT1X", "dot1x"))&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/props.conf                      EVAL-bytes = bytes_in + bytes_out&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/props.conf                      EVAL-dest_mac = case(dest_mac == "Unknown MAC", NULL, isnotnull(dest_mac), lower(replace(dest_mac,"^([0-9a-fA-F]{2})([0-9a-fA-F]{2}).([0-9a-fA-F]{2})([0-9a-fA-F]{2}).([0-9a-fA-F]{2})([0-9a-fA-F]{2})","\1:\2:\3:\4:\5:\6")))&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/props.conf                      EVAL-dvc = coalesce(dvc, host)&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/props.conf                      EVAL-product = case(isnotnull(filename) AND isnotnull(filename_line), "WLC", isnotnull(direct_ap_mac), "AP", isnull(filename) AND isnull(filename_line) AND isnull(direct_ap_mac), "IOS")&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/props.conf                      EVAL-reliable_time = if(reliable_time == "&lt;/EM&gt;", "false", "true")&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/props.conf                      EVAL-src_int = replace(src_int, "(\S+)\s(\d+)", "\1\2")&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/props.conf                      EVAL-src_mac = case(src_mac == "Unknown MAC", NULL, isnotnull(src_mac), lower(replace(src_mac,"^([0-9a-fA-F]{2})([0-9a-fA-F]{2}).([0-9a-fA-F]{2})([0-9a-fA-F]{2}).([0-9a-fA-F]{2})([0-9a-fA-F]{2})","\1:\2:\3:\4:\5:\6")))&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/props.conf                      EVAL-vendor = "Cisco"&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/props.conf                      EXTRACT-cisco-ios-BGP-3-IO_INIT = IO_INIT(\s)?:\s+Initialization failed: (?Failed accepting a replicated session) unable to find\s+nbr\s+*?(?\S+)*&lt;/P&gt;

&lt;P&gt;and for the second:&lt;BR /&gt;
&lt;EM&gt;/opt/splunk/etc/system/default/transforms.conf                                 MV_ADD = False&lt;BR /&gt;
/opt/splunk/etc/apps/Splunk_SA_CIM/default/transforms.conf                     REGEX = ^.&lt;/EM&gt;&lt;A href="https://community.splunk.com/.+" target="_blank"&gt;\/&lt;/A&gt;&lt;EM&gt;mod(?:alert|workflow).log$&lt;BR /&gt;
/opt/splunk/etc/apps/Splunk_SA_CIM/default/transforms.conf                     SOURCE_KEY = MetaData:Source&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 WRITE_META = False&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      [force_sourcetype_cisco_traceback]&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 CAN_OPTIMIZE = True&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 CLEAN_KEYS = True&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 DEFAULT_VALUE =&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 DEPTH_LIMIT = 1000&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      DEST_KEY = MetaData:Sourcetype&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      FORMAT = sourcetype::cisco:ios:traceback&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 KEEP_EMPTY_VALS = False&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 LOOKAHEAD = 4096&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 MATCH_LIMIT = 100000&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 MV_ADD = False&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      REGEX = -Traceback=&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 SOURCE_KEY = _raw&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 WRITE_META = False&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      [force_sourcetype_for_cisco_ios]&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 CAN_OPTIMIZE = True&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 CLEAN_KEYS = True&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 DEFAULT_VALUE =&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 DEPTH_LIMIT = 1000&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      DEST_KEY = MetaData:Sourcetype&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      FORMAT = sourcetype::cisco:ios&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 KEEP_EMPTY_VALS = False&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 LOOKAHEAD = 4096&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 MATCH_LIMIT = 100000&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 MV_ADD = False&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      REGEX = (?:(?:\S+)\s)?(?:(?:\d+)?:\s(?:.\S+:\s)?(?:[.*])?(?:.+)?)?:\s+(?:%|#)(?:(?!POLICY_ENGINE|UCSM|FWSM|ASA|PIX|ACE)[A-Z0-9&lt;/EM&gt;]+)-(?:(?:[A-Z012_]&lt;EM&gt;(?:-?[A-Z_][^-]&lt;/EM&gt;))-?)?(?:[0-7])-(?:[A-Z0-9_]+):(?:(?:[A-Za-z0-9_]+):)?\s(?:.+)&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 SOURCE_KEY = &lt;EM&gt;raw&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 WRITE_META = False&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      [force_sourcetype_for_cisco_ios-rfc5424]&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 CAN_OPTIMIZE = True&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 CLEAN_KEYS = True&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 DEFAULT_VALUE =&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 DEPTH_LIMIT = 1000&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      DEST_KEY = MetaData:Sourcetype&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      FORMAT = sourcetype::cisco:ios&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 KEEP_EMPTY_VALS = False&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 LOOKAHEAD = 4096&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 MATCH_LIMIT = 100000&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 MV_ADD = False&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      REGEX = (?:&amp;lt;(?:\d+)&amp;gt;)(?:\d+) (?:\S+) (?:\S+)? (?:\d+)\s+(?:\S+)\s+(?:\S+)(?:.+)?:\s+(?:%|#)(?:(?!POLICY_ENGINE|UCSM|FWSM|ASA|PIX|ACE)[A-Z0-9&lt;/EM&gt;]+)-(?:(?:[A-Z0-2_]&lt;EM&gt;(?:-?[A-Z_][^-]&lt;/EM&gt;))-?)?(?:[0-7])-(?:[A-Z0-9_]+):\s(?:.+)&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 SOURCE_KEY = &lt;EM&gt;raw&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 WRITE_META = False&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      [force_sourcetype_for_cisco_ios-xe]&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 CAN_OPTIMIZE = True&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 CLEAN_KEYS = True&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 DEFAULT_VALUE =&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 DEPTH_LIMIT = 1000&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      DEST_KEY = MetaData:Sourcetype&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      FORMAT = sourcetype::cisco:ios&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 KEEP_EMPTY_VALS = False&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 LOOKAHEAD = 4096&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 MATCH_LIMIT = 100000&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 MV_ADD = False&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      REGEX = (?:(?:\S+)\s)?(?:(?:\d+)?:\s(?:.\S+:\s)?(?:[.*])?(?:.+)?)?:\s+(?:%|#)(?:(?!POLICY_ENGINE|UCSM|FWSM|ASA|PIX|ACE)[A-Z0-9&lt;/EM&gt;]+)-(?:(?:[A-Z012_]&lt;EM&gt;(?:-?[A-Z_][^-]&lt;/EM&gt;))-?)?(?:[0-7])-(?:[A-Z0-9_]+):(?:(?:[A-Za-z0-9_]+):)?\s(?:.+)&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 SOURCE_KEY = &lt;EM&gt;raw&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 WRITE_META = False&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      [force_sourcetype_for_cisco_ios-xr]&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 CAN_OPTIMIZE = True&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 CLEAN_KEYS = True&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 DEFAULT_VALUE =&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 DEPTH_LIMIT = 1000&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      DEST_KEY = MetaData:Sourcetype&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      FORMAT = sourcetype::cisco:ios&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 KEEP_EMPTY_VALS = False&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 LOOKAHEAD = 4096&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 MATCH_LIMIT = 100000&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 MV_ADD = False&lt;BR /&gt;
/opt/splunk/etc/apps/TA-cisco_ios/default/transforms.conf                      REGEX = (?:(?:\S+)\s)?(?:\d+):\s(?:(?:\S+)\s)?(?:(?:[A-Z]+)\/(?:\d+)\/(?:[A-Z0-9]+)\/(?:[A-Z0-9]+)):(?:.+)\s?:\s?(?:[A-Za-z0-9&lt;/EM&gt;]+)[(?:\d+)]:\s+%(?:[A-Za-z0-9_]+)-(?:[A-Za-z0-9_]+)-(?:(?:[A-Za-z12_]&lt;EM&gt;(?:-?[A-Za-z_][^-]&lt;/EM&gt;))-?)?(?:[0-7])-(?:[A-Z0-9_]+)\s:\s(?:.+)&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 SOURCE_KEY = _raw&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 WRITE_META = False&lt;BR /&gt;
/opt/splunk/etc/apps/Splunk_TA_nix/default/transforms.conf                     [fs_notification_change_type_lookup]&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 CAN_OPTIMIZE = True&lt;BR /&gt;
/opt/splunk/etc/system/default/transforms.conf                                 CLEAN_KEYS = True*&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:21:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397445#M70858</guid>
      <dc:creator>wralph_EPACN</dc:creator>
      <dc:date>2020-09-29T23:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change _internal index sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397446#M70859</link>
      <description>&lt;P&gt;Ok, so there are four transforms that set that sourcetype:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;force_sourcetype_for_cisco_ios
force_sourcetype_for_cisco_ios-rfc5424
force_sourcetype_for_cisco_ios-xe
force_sourcetype_for_cisco_ios-xr
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You'll need to check how these transforms are triggered from props.conf, to see if any of that could accidentally apply to internal logs.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 08:34:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397446#M70859</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-02-27T08:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: How do I change _internal index sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397447#M70860</link>
      <description>&lt;P&gt;@wralph_EPACN  please accept an answer if it solved/helped it and upvote it. Otherwise let us know how can we help further&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 11:07:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-change-internal-index-sourcetype/m-p/397447#M70860</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2019-03-01T11:07:52Z</dc:date>
    </item>
  </channel>
</rss>

