- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


I've got a file that was previously indexed as sourcetype1 but I want it to be customer_sourcetype2. I thought there was a way in splunk to have splunk, at search time, reassign that search type. Am I wrong?
I thought I could do this with a props.conf entry:
[source::/path/to/file/filename.log]
sourcetype = customer_sourcetype2
Someone correct my understanding?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Perhaps have a look here:
http://docs.splunk.com/Documentation/Splunk/6.0/Data/Renamesourcetypes
This is the closest you are going to get, I'm afraid. sourcetype
is one of those things that cannot be truly changed after the data has been indexed.
/K
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Perhaps have a look here:
http://docs.splunk.com/Documentation/Splunk/6.0/Data/Renamesourcetypes
This is the closest you are going to get, I'm afraid. sourcetype
is one of those things that cannot be truly changed after the data has been indexed.
/K
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Thank you!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yeah, well, no. It's like;
[sourcetype_1]
rename = sourcetype_2
The renaming can only be done on a [sourcetype]
, not a [source::/path/to/file]
or a [host::hostname]
.
/k
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Yea - looks like that's the case.
rename =
* Renames [
* With renaming, you can search for the [
* To search for the original source type without renaming it, use the field _sourcetype.
* Data from a a renamed sourcetype will only use the search-time configuration for the target sourcetype.
Field extractions (REPORTS/EXTRAXCT) for this stanza sourcetype will be ignored.
* Defaults to empty.
From: http://docs.splunk.com/Documentation/Splunk/5.0.2/Admin/Propsconf
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Oh wow thanks! I'm guessing that won't work if I can only specify the source. There are other sources with the same sourcetype1 which I don't want to change sourcetypes for.
[source::/path/to/file/filename.log]
rename = customer_sourcetype2
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Just found that as well...
