Getting Data In

Convert sourcetype

sloshburch
Ultra Champion

I've got a file that was previously indexed as sourcetype1 but I want it to be customer_sourcetype2. I thought there was a way in splunk to have splunk, at search time, reassign that search type. Am I wrong?

I thought I could do this with a props.conf entry:

[source::/path/to/file/filename.log]
    sourcetype = customer_sourcetype2

Someone correct my understanding?

Tags (1)
0 Karma
1 Solution

kristian_kolb
Ultra Champion

Perhaps have a look here:

http://docs.splunk.com/Documentation/Splunk/6.0/Data/Renamesourcetypes

This is the closest you are going to get, I'm afraid. sourcetype is one of those things that cannot be truly changed after the data has been indexed.

/K

View solution in original post

kristian_kolb
Ultra Champion

Perhaps have a look here:

http://docs.splunk.com/Documentation/Splunk/6.0/Data/Renamesourcetypes

This is the closest you are going to get, I'm afraid. sourcetype is one of those things that cannot be truly changed after the data has been indexed.

/K

sloshburch
Ultra Champion

Thank you!

0 Karma

kristian_kolb
Ultra Champion

yeah, well, no. It's like;

[sourcetype_1]
rename = sourcetype_2

The renaming can only be done on a [sourcetype], not a [source::/path/to/file] or a [host::hostname].

/k

0 Karma

sloshburch
Ultra Champion

Yea - looks like that's the case.

rename =
* Renames [] as
* With renaming, you can search for the [] with sourcetype=
* To search for the original source type without renaming it, use the field _sourcetype.
* Data from a a renamed sourcetype will only use the search-time configuration for the target sourcetype.
Field extractions (REPORTS/EXTRAXCT) for this stanza sourcetype will be ignored.
* Defaults to empty.

From: http://docs.splunk.com/Documentation/Splunk/5.0.2/Admin/Propsconf

0 Karma

sloshburch
Ultra Champion

Oh wow thanks! I'm guessing that won't work if I can only specify the source. There are other sources with the same sourcetype1 which I don't want to change sourcetypes for.

[source::/path/to/file/filename.log]
rename = customer_sourcetype2

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Just found that as well...

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...