We have log data that fits perfectly into the access_combined
pretrained sourcetype. All looks perfect except the fact that the access_combined
sourcetype doesn't conform to our standard sourcetype naming conventions. Is there a way around it? changing the name, alias, etc....
Under Settings->Data->Source Types you can see the access_combined sourcetype. Just clone it with a new name.
Or through the props.conf, you can just rename the stanza and restart Splunk.
Hi @ddrillic,
I'm not sure if this answers your question, but have you checked out the "Create Field Aliases" page in Splunk Docs?
https://docs.splunk.com/Documentation/Splunk/7.1.2/Knowledge/Addaliasestofields
Happy Splunking!