Getting Data In

How to send specific logs to a sourcetype?

deepthi5
Path Finder

Hello All,

 

I have query index=xxxx sourcetype=xxx_* NOT(ASA) which actually filters logs that are not ASA from 4 sourcetypes , i want to send these resulted logs to a new sourcetype call xxx_analmoly 

 

Is it possible if yes , how can i achieve this 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @deepthi5,

no, I'm sorry: when an event is indexed isn't possible to change the sourcetype.

You have to define the new sourcetype rules (regexes) and override the original value before indexing, following the steps described at https://docs.splunk.com/Documentation/Splunk/9.0.2/Data/Advancedsourcetypeoverrides#:~:text=You%20ca....

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...