I tried out the option "source name override" when setting up a UDP data input to replace "UDP:514" with "mynetworkSyslogs".
After making this change, can I permanently change the source name of exisiting data from this input to match the change?
I have tried doing: source="udp:514" | replace "udp:514" with "mynetworkSyslogs"
in the search bar but this does not seem to make a permanent change.
You can't modify existing meta data. You have to re-index the old data.
You can't modify existing meta data. You have to re-index the old data.
You have to re-feed the log files. With 4.2 I think there're some new features for re-indexing. But I haven't checked them yet.
Thanks,
Though this seems to be a quite a limitation in Splunk.
I have been unable to locate any clear information on how to re-index my data. How do I do this?