Hi,
I want to rename a sourcetype, but the following isn't working:
[log4j]
KV_MODE = auto
ANNOTATE_PUNCT = false
TRANSFORMS-changesourcetype = set_fc_catalina_out
[set_fc_catalina_out]
FORMAT = sourcetype::fc_catalina_out
DEST_KEY = MetaData:Sourcetype
Am I missing something?
# with [<sourcetype>]:
rename = <string>
* Renames [<sourcetype>] as <string>
* With renaming, you can search for the [<sourcetype>] with
sourcetype=<string>
* To search for the original source type without renaming it, use the  field _sourcetype.
* Data from a a renamed sourcetype will only use the search-time configuration for the target
sourcetype. Field extractions (REPORTS/EXTRACT) for this stanza sourcetype will be ignored.
* Defaults to empty.
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		It depends where in the process you are trying to rename this source type. Are you trying to rename this at the search layer or index layer?
What you are doing will rename the source type at parsing / index time.
If you are trying to do this to data that has already been indexed, you simply need to rename the data source:
[log4j]
rename = fc_catalina_out
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Post your configurations.
Doing it at the indexer layer, but it's not working. Would the indexers need to be restarted?
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Once you change a props / transforms, the indexers do need to be restarted.
Tried all this - still no change.
