Getting Data In

Change source name for exisiting data.

Explorer

I tried out the option "source name override" when setting up a UDP data input to replace "UDP:514" with "mynetworkSyslogs".

After making this change, can I permanently change the source name of exisiting data from this input to match the change?

I have tried doing: source="udp:514" | replace "udp:514" with "mynetworkSyslogs" in the search bar but this does not seem to make a permanent change.

Tags (2)
1 Solution

Path Finder

You can't modify existing meta data. You have to re-index the old data.

View solution in original post

Path Finder

You can't modify existing meta data. You have to re-index the old data.

View solution in original post

Path Finder

You have to re-feed the log files. With 4.2 I think there're some new features for re-indexing. But I haven't checked them yet.

0 Karma

Explorer

Thanks,
Though this seems to be a quite a limitation in Splunk.

I have been unable to locate any clear information on how to re-index my data. How do I do this?

0 Karma