This documentation does not apply to the most recent version of Splunk.
This documentation applies to the following versions of Splunk: 3.0.1 , 3.0.2 , 3.1 , 3.1.1 , 3.1.2 , 3.1.3 , 3.1.4
Use these instructions if you need to assign a sourcetype based on a source.
This will only impact new data coming in following your configuration change. If you want to correct the sourcetype displayed in SplunkWeb for data that has already been indexed, you will need to create an alias instead.
Create a stanza for your source in $SPLUNK_HOME/etc/bundles/local/props.conf and set a sourcetype = attribute:
[source::.../var/log/anaconda.log(.\d+)?] sourcetype = anaconda
This will set any events from sources containing the string /var/log/anaconda.log followed by any number of numeric characters to sourcetype::anaconda.
Learn more about props.conf.