Getting Data In

Is it possible to edit a sourcetype after its creation?

atemourt
Engager

Hello Splunkers,

Is it possible to edit a sourcetype after its creation?

Thank you in advance!
Afroditi

0 Karma
1 Solution

mayurr98
Super Champion

hey @atemourt
There are two ways to edit the sourcetype manually:
first way as mention by @florianduhme and second way is by editing props.conf through CLI.
you will find this file in \etc\system\local OR \etc\system\<appname>\local
After editing the configuration restart the Splunk instance. You will see changes only for the recent data(newly indexed data) and not the historical data(already indexed data)
Refer to Props.conf Splunk doc for the detailed options available for modifying props.conf.

NOTE: You cannot change the source type after your data has been indexed. You will have to delete it and reindex.

let me know if this helps!

View solution in original post

ddrillic
Ultra Champion

We dealt with a related issue recently at Is it possible to generate the sourcetype based on the source?

0 Karma

mayurr98
Super Champion

hey @atemourt
There are two ways to edit the sourcetype manually:
first way as mention by @florianduhme and second way is by editing props.conf through CLI.
you will find this file in \etc\system\local OR \etc\system\<appname>\local
After editing the configuration restart the Splunk instance. You will see changes only for the recent data(newly indexed data) and not the historical data(already indexed data)
Refer to Props.conf Splunk doc for the detailed options available for modifying props.conf.

NOTE: You cannot change the source type after your data has been indexed. You will have to delete it and reindex.

let me know if this helps!

atemourt
Engager

Thank you @mayurr98!

0 Karma

florianduhme
Path Finder

The only way I know is to go into Settings --> Sourcetypes and click on "Edit". There you can edit your settings of the sourcetype, but unfortunately, you won't get a preview of your changed settings or any sample data.
But this is probably not what you are looking for?

I guess you would need to create a new source type in order to see a preview of it with your data.

0 Karma

atemourt
Engager

Thank you @florianduhme!

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...