Getting Data In

Would I be able to rename a "Source Type" after the data got already indexed into Splunk?

clyde772
Communicator

Would I be able to rename a "Source Type" after the data got already indexed into Splunk?

Can I rename a type of pattern data into another "Souce Type"

or

I have to delete the type of source and reindex?

Tags (1)

jrodman
Splunk Employee
Splunk Employee

In addition, you can make splunk treat sourcetype A as if it were sourcetype B for search purposes.

http://www.splunk.com/base/Documentation/4.1.2/Admin/Renamesourcetypes

This only allows you to cause ALL of sourcetype A to now be considered B.

Simeon
Splunk Employee
Splunk Employee

You Cannot rename a Source Type after it has already been indexed. However, you can use tags or aliases to alter the way you identify those events:

http://www.splunk.com/base/Documentation/latest/Knowledge/Abouttagsandaliases

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...