Getting Data In

How to rename sourcetype at index time?

rsannala
Engager

Hi Experts,

I would like rename sourcetype at index time with below config.

props.conf

[source::test/source.txt]

TRANSFORMS-sourcetype = newsourcetype

Transforms.conf

[newsourcetype]

SOURCE_KEY = MetaData:Sourcetype
REGEX = regex to match existing sourcetype
FORMAT = newsourcetype
DEST_KEY = MetaData:Sourcetype

 

Now I would like apply below settings on new sourcetype. 

[newsourcetype]

TZ=

Linebreaker=
Truncate=

etc..

will it work this way ? Please let me know.

 

Thanks.

Ram

 

 

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rsannala,

yes it's possible as described at https://docs.splunk.com/Documentation/Splunk/latest/Data/Advancedsourcetypeoverrides

remember that you have to perform this transformation on the first Splunk full instance, an Heavy Forwarder (if present) or an Indexer.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...