Getting Data In

Why am I unable to rename sourcetypes with my current attempts?

juraj
Explorer

Hello everyone,

I see that this question has been posted many times, but none of the suggested fixes appear to work for me.
I have several data sources indexed with a wrong sourcetype.
E.g. my sourcetypes are log.1, log.2, log.3 ... and I'd like to rename them to "log" at search time.

I put in the props.conf on the search head the following:

[log*]
rename = log

but it doesn't seem to work after running the | extract reload=t.
I have also tried [log...] which should accomplish the same thing, or the somewhat arcane looking [(?:::){0}log*], but none of these appear to work.

Am I doing something obviously wrong here? I'm not touching transforms.conf, but per docs, I shouldn't really need to, and the simple two lines in props.conf on the search head should work.

Many thanks!

J.

0 Karma

woodcock
Esteemed Legend

Like this in props.conf (it works, I tested it):

[(?:::){0}log*]
rename = log
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...