I've got a file that was previously indexed as sourcetype1 but I want it to be customer_sourcetype2. I thought there was a way in splunk to have splunk, at search time, reassign that search type. Am I wrong?
I thought I could do this with a props.conf entry:
[source::/path/to/file/filename.log]
sourcetype = customer_sourcetype2
Someone correct my understanding?
Perhaps have a look here:
http://docs.splunk.com/Documentation/Splunk/6.0/Data/Renamesourcetypes
This is the closest you are going to get, I'm afraid. sourcetype
is one of those things that cannot be truly changed after the data has been indexed.
/K
Perhaps have a look here:
http://docs.splunk.com/Documentation/Splunk/6.0/Data/Renamesourcetypes
This is the closest you are going to get, I'm afraid. sourcetype
is one of those things that cannot be truly changed after the data has been indexed.
/K
Thank you!
yeah, well, no. It's like;
[sourcetype_1]
rename = sourcetype_2
The renaming can only be done on a [sourcetype]
, not a [source::/path/to/file]
or a [host::hostname]
.
/k
Yea - looks like that's the case.
rename =
* Renames [
* With renaming, you can search for the [
* To search for the original source type without renaming it, use the field _sourcetype.
* Data from a a renamed sourcetype will only use the search-time configuration for the target sourcetype.
Field extractions (REPORTS/EXTRAXCT) for this stanza sourcetype will be ignored.
* Defaults to empty.
From: http://docs.splunk.com/Documentation/Splunk/5.0.2/Admin/Propsconf
Oh wow thanks! I'm guessing that won't work if I can only specify the source. There are other sources with the same sourcetype1 which I don't want to change sourcetypes for.
[source::/path/to/file/filename.log]
rename = customer_sourcetype2
Just found that as well...