Getting Data In

Change source name for exisiting data.

Mr_Robaloba
Explorer

I tried out the option "source name override" when setting up a UDP data input to replace "UDP:514" with "mynetworkSyslogs".

After making this change, can I permanently change the source name of exisiting data from this input to match the change?

I have tried doing: source="udp:514" | replace "udp:514" with "mynetworkSyslogs" in the search bar but this does not seem to make a permanent change.

Tags (2)
1 Solution

wollinet
Path Finder

You can't modify existing meta data. You have to re-index the old data.

View solution in original post

wollinet
Path Finder

You can't modify existing meta data. You have to re-index the old data.

wollinet
Path Finder

You have to re-feed the log files. With 4.2 I think there're some new features for re-indexing. But I haven't checked them yet.

0 Karma

Mr_Robaloba
Explorer

Thanks,
Though this seems to be a quite a limitation in Splunk.

I have been unable to locate any clear information on how to re-index my data. How do I do this?

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...