Getting Data In

Why am I unable to rename sourcetypes with my current attempts?

juraj
Explorer

Hello everyone,

I see that this question has been posted many times, but none of the suggested fixes appear to work for me.
I have several data sources indexed with a wrong sourcetype.
E.g. my sourcetypes are log.1, log.2, log.3 ... and I'd like to rename them to "log" at search time.

I put in the props.conf on the search head the following:

[log*]
rename = log

but it doesn't seem to work after running the | extract reload=t.
I have also tried [log...] which should accomplish the same thing, or the somewhat arcane looking [(?:::){0}log*], but none of these appear to work.

Am I doing something obviously wrong here? I'm not touching transforms.conf, but per docs, I shouldn't really need to, and the simple two lines in props.conf on the search head should work.

Many thanks!

J.

0 Karma

woodcock
Esteemed Legend

Like this in props.conf (it works, I tested it):

[(?:::){0}log*]
rename = log
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...