Getting Data In

Why am I unable to rename sourcetypes with my current attempts?

juraj
Explorer

Hello everyone,

I see that this question has been posted many times, but none of the suggested fixes appear to work for me.
I have several data sources indexed with a wrong sourcetype.
E.g. my sourcetypes are log.1, log.2, log.3 ... and I'd like to rename them to "log" at search time.

I put in the props.conf on the search head the following:

[log*]
rename = log

but it doesn't seem to work after running the | extract reload=t.
I have also tried [log...] which should accomplish the same thing, or the somewhat arcane looking [(?:::){0}log*], but none of these appear to work.

Am I doing something obviously wrong here? I'm not touching transforms.conf, but per docs, I shouldn't really need to, and the simple two lines in props.conf on the search head should work.

Many thanks!

J.

0 Karma

woodcock
Esteemed Legend

Like this in props.conf (it works, I tested it):

[(?:::){0}log*]
rename = log
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...