Getting Data In

Create aliases for common sourcetypes


I'd like to create a custom name for a common sourcetype. For instance:


sourcetype = custom_syslog



Some configuration to make this custom sourcetype

format logs like the syslog sourcetype would be


sourcetype = custom_syslog

Rename does this in the reverse. I could rename my custom field to syslog with 'rename = syslog' in my props.conf, but that wouldn't help me. I want the behavior, but not the name of the default sourcetypes.

0 Karma


I am not sure to understand perfectly what you try to do. To me it seems impossible to change de behavior since its linked to a specific set of data. It will always behave as it was doing at the begining
Please if this is not enought, provide more details

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!