Getting Data In

Convert sourcetype

sloshburch
Ultra Champion

I've got a file that was previously indexed as sourcetype1 but I want it to be customer_sourcetype2. I thought there was a way in splunk to have splunk, at search time, reassign that search type. Am I wrong?

I thought I could do this with a props.conf entry:

[source::/path/to/file/filename.log]
    sourcetype = customer_sourcetype2

Someone correct my understanding?

Tags (1)
0 Karma
1 Solution

kristian_kolb
Ultra Champion

Perhaps have a look here:

http://docs.splunk.com/Documentation/Splunk/6.0/Data/Renamesourcetypes

This is the closest you are going to get, I'm afraid. sourcetype is one of those things that cannot be truly changed after the data has been indexed.

/K

View solution in original post

kristian_kolb
Ultra Champion

Perhaps have a look here:

http://docs.splunk.com/Documentation/Splunk/6.0/Data/Renamesourcetypes

This is the closest you are going to get, I'm afraid. sourcetype is one of those things that cannot be truly changed after the data has been indexed.

/K

sloshburch
Ultra Champion

Thank you!

0 Karma

kristian_kolb
Ultra Champion

yeah, well, no. It's like;

[sourcetype_1]
rename = sourcetype_2

The renaming can only be done on a [sourcetype], not a [source::/path/to/file] or a [host::hostname].

/k

0 Karma

sloshburch
Ultra Champion

Yea - looks like that's the case.

rename =
* Renames [] as
* With renaming, you can search for the [] with sourcetype=
* To search for the original source type without renaming it, use the field _sourcetype.
* Data from a a renamed sourcetype will only use the search-time configuration for the target sourcetype.
Field extractions (REPORTS/EXTRAXCT) for this stanza sourcetype will be ignored.
* Defaults to empty.

From: http://docs.splunk.com/Documentation/Splunk/5.0.2/Admin/Propsconf

0 Karma

sloshburch
Ultra Champion

Oh wow thanks! I'm guessing that won't work if I can only specify the source. There are other sources with the same sourcetype1 which I don't want to change sourcetypes for.

[source::/path/to/file/filename.log]
rename = customer_sourcetype2

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Just found that as well...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...