Getting Data In

Convert sourcetype

sloshburch
Ultra Champion

I've got a file that was previously indexed as sourcetype1 but I want it to be customer_sourcetype2. I thought there was a way in splunk to have splunk, at search time, reassign that search type. Am I wrong?

I thought I could do this with a props.conf entry:

[source::/path/to/file/filename.log]
    sourcetype = customer_sourcetype2

Someone correct my understanding?

Tags (1)
0 Karma
1 Solution

kristian_kolb
Ultra Champion

Perhaps have a look here:

http://docs.splunk.com/Documentation/Splunk/6.0/Data/Renamesourcetypes

This is the closest you are going to get, I'm afraid. sourcetype is one of those things that cannot be truly changed after the data has been indexed.

/K

View solution in original post

kristian_kolb
Ultra Champion

Perhaps have a look here:

http://docs.splunk.com/Documentation/Splunk/6.0/Data/Renamesourcetypes

This is the closest you are going to get, I'm afraid. sourcetype is one of those things that cannot be truly changed after the data has been indexed.

/K

sloshburch
Ultra Champion

Thank you!

0 Karma

kristian_kolb
Ultra Champion

yeah, well, no. It's like;

[sourcetype_1]
rename = sourcetype_2

The renaming can only be done on a [sourcetype], not a [source::/path/to/file] or a [host::hostname].

/k

0 Karma

sloshburch
Ultra Champion

Yea - looks like that's the case.

rename =
* Renames [] as
* With renaming, you can search for the [] with sourcetype=
* To search for the original source type without renaming it, use the field _sourcetype.
* Data from a a renamed sourcetype will only use the search-time configuration for the target sourcetype.
Field extractions (REPORTS/EXTRAXCT) for this stanza sourcetype will be ignored.
* Defaults to empty.

From: http://docs.splunk.com/Documentation/Splunk/5.0.2/Admin/Propsconf

0 Karma

sloshburch
Ultra Champion

Oh wow thanks! I'm guessing that won't work if I can only specify the source. There are other sources with the same sourcetype1 which I don't want to change sourcetypes for.

[source::/path/to/file/filename.log]
rename = customer_sourcetype2

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Just found that as well...

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...