After setting up a listen on UDP port (514) for syslog using inputs.conf, I tried to change the sourcetype from syslog (set in inputs.conf) to syslog_nf. Thus, i used the first method
sourcetype = syslog_nf
this doesn't change anything!
However, when I do:
rename = syslog_nf
the change happens! Does anyone have any idea about this?
Try changing the sourcetype directly in inputs.conf. Its simpler than doing the same thing through props.conf.
First define sourcetye in transforms.conf. Something like
FORMAT = sourcetype::syslong_nf
DEST_KEY = MetaData:Sourcetype
Note: Check if you need any REGEX.
Then, in props.conf
TRANSFORMS-changesourcetype = set_sourcetype_syslog_nf
But, As somesoni2 commented, i would also suggest to set sourcetypes in inputs.conf
View solution in original post