I've got a file that was previously indexed as sourcetype1 but I want it to be customer_sourcetype2. I thought there was a way in splunk to have splunk, at search time, reassign that search type. Am I wrong?
I thought I could do this with a props.conf entry:
[source::/path/to/file/filename.log] sourcetype = customer_sourcetype2
Someone correct my understanding?
Perhaps have a look here:
This is the closest you are going to get, I'm afraid.
sourcetype is one of those things that cannot be truly changed after the data has been indexed.
Oh wow thanks! I'm guessing that won't work if I can only specify the source. There are other sources with the same sourcetype1 which I don't want to change sourcetypes for.
rename = customer_sourcetype2
Yea - looks like that's the case.
* Renames [
* With renaming, you can search for the [
* To search for the original source type without renaming it, use the field _sourcetype.
* Data from a a renamed sourcetype will only use the search-time configuration for the target sourcetype.
Field extractions (REPORTS/EXTRAXCT) for this stanza sourcetype will be ignored.
* Defaults to empty.
yeah, well, no. It's like;
rename = sourcetype_2
The renaming can only be done on a
[sourcetype], not a
[source::/path/to/file] or a