I want to rename a sourcetype, but the following isn't working:
[log4j] KV_MODE = auto ANNOTATE_PUNCT = false TRANSFORMS-changesourcetype = set_fc_catalina_out [set_fc_catalina_out] FORMAT = sourcetype::fc_catalina_out DEST_KEY = MetaData:Sourcetype
Am I missing something?
It depends where in the process you are trying to rename this source type. Are you trying to rename this at the search layer or index layer?
What you are doing will rename the source type at parsing / index time.
If you are trying to do this to data that has already been indexed, you simply need to rename the data source:
[log4j] rename = fc_catalina_out
# with [<sourcetype>]: rename = <string> * Renames [<sourcetype>] as <string> * With renaming, you can search for the [<sourcetype>] with sourcetype=<string> * To search for the original source type without renaming it, use the field _sourcetype. * Data from a a renamed sourcetype will only use the search-time configuration for the target sourcetype. Field extractions (REPORTS/EXTRACT) for this stanza sourcetype will be ignored. * Defaults to empty.