Splunk Search

How to rename the sourcetype without involving our vendor at the point of ingest so that I can perform field extraction?

ekolseth
Loves-to-Learn

We have a cloud instance of Splunk and a vendor whose forwarders we do not control sending data to our instance. I am trying to extract fields from their data but their sourcetypes are large alpha-numeric values and there are 100+ for just the Audit log (ex. 812b245d-1da3-43a5-a6f8-0fbdc4f9286cAudit-too_small)  This is making field extraction difficult to perform.

How can I rename the sourcetype on these without involving our vendor (who is very Splunk illiterate) at the point of ingest so that I can perform field extractions? The sourcetype rename utility within Splunk seems to work but with over 100+ such sourcetypes this method is rather unwieldy and I am looking for a cleaner method.

Much thanks

Labels (1)
0 Karma

PickleRick
Ultra Champion

You can overwrite the metadata (in this case - the sourcetype) using this technique

https://docs.splunk.com/Documentation/Splunk/8.2.5/Forwarding/Routeandfilterdatad

Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...