Hello Splunkers,
Is it possible to edit a sourcetype after its creation?
Thank you in advance!
Afroditi
hey @atemourt
There are two ways to edit the sourcetype manually:
first way as mention by @florianduhme and second way is by editing props.conf
through CLI.
you will find this file in \etc\system\local
OR \etc\system\<appname>\local
After editing the configuration restart the Splunk instance. You will see changes only for the recent data(newly indexed data) and not the historical data(already indexed data)
Refer to Props.conf Splunk doc for the detailed options available for modifying props.conf.
NOTE: You cannot change the source type after your data has been indexed. You will have to delete it and reindex.
let me know if this helps!
We dealt with a related issue recently at Is it possible to generate the sourcetype based on the source?
hey @atemourt
There are two ways to edit the sourcetype manually:
first way as mention by @florianduhme and second way is by editing props.conf
through CLI.
you will find this file in \etc\system\local
OR \etc\system\<appname>\local
After editing the configuration restart the Splunk instance. You will see changes only for the recent data(newly indexed data) and not the historical data(already indexed data)
Refer to Props.conf Splunk doc for the detailed options available for modifying props.conf.
NOTE: You cannot change the source type after your data has been indexed. You will have to delete it and reindex.
let me know if this helps!
Thank you @mayurr98!
The only way I know is to go into Settings --> Sourcetypes and click on "Edit". There you can edit your settings of the sourcetype, but unfortunately, you won't get a preview of your changed settings or any sample data.
But this is probably not what you are looking for?
I guess you would need to create a new source type in order to see a preview of it with your data.
Thank you @florianduhme!