Archive
Highlighted

Is it possible to rename a pretrained sourcetype?

Ultra Champion

We have log data that fits perfectly into the access_combined pretrained sourcetype. All looks perfect except the fact that the access_combined sourcetype doesn't conform to our standard sourcetype naming conventions. Is there a way around it? changing the name, alias, etc....

Tags (1)
0 Karma
Highlighted

Re: Is it possible to rename a pretrained sourcetype?

Splunk Employee
Splunk Employee

Hi @ddrillic,

I'm not sure if this answers your question, but have you checked out the "Create Field Aliases" page in Splunk Docs?

https://docs.splunk.com/Documentation/Splunk/7.1.2/Knowledge/Addaliasestofields

Happy Splunking!

0 Karma
Highlighted

Re: Is it possible to rename a pretrained sourcetype?

Path Finder

Under Settings->Data->Source Types you can see the access_combined sourcetype. Just clone it with a new name.

Or through the props.conf, you can just rename the stanza and restart Splunk.

0 Karma