# Pipeline source name change not sticking

**URL:** <https://community.graylog.org/t/pipeline-source-name-change-not-sticking/5639>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules, debuggingpl\
**Created:** [June 18, 2018, 12:54pm UTC](https://community.graylog.org/t/pipeline-source-name-change-not-sticking/5639 "2018-06-18T12:54:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![uclnj](https://avatars.discourse-cdn.com/v4/letter/u/e480ec/32.png) [@uclnj](https://community.graylog.org/u/uclnj)\
**Post date:** [June 18, 2018, 12:54pm UTC](https://community.graylog.org/t/pipeline-source-name-change-not-sticking/5639/1 "2018-06-18T12:54:08Z")

</div>

I have two pipelines to change server names - I can watch the Graylog log file showing the source name being swapped

 ![31](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/5/5e0cc5d898eee714241b9ae8b0520afd486fbc9b.png)

but when I view look at the search results, the source name is back to “brunswickxtm”

 ![12](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/f/f03284408ac3d5fb35a48bdacbdf6e9c60613c9d.png)

however an **identical** rule for another firewall works and the source name change is reflected in the search results.

Rule that works

```
rule "Email AFS"
when
  to_string($message.source) == "EMAILAFS"
then
  set_field("source", "WatchGuard M300");
end

```

Rule that doesn’t work.

```
rule "BRXTM"
when
  to_string($message.source) == "BRUNSWICKXTM"
then
  debug($message.source);
  set_field("source", "WatchGuard XTM26W");
  debug($message.source);
end

```

The debug messages trigger when watching the log.

---

<div class="post-metadata">

**Author:** ![uclnj](https://avatars.discourse-cdn.com/v4/letter/u/e480ec/32.png) [@uclnj](https://community.graylog.org/u/uclnj)\
**Post date:** [June 18, 2018, 12:57pm UTC](https://community.graylog.org/t/pipeline-source-name-change-not-sticking/5639/2 "2018-06-18T12:57:25Z")

</div>

I took a chance, deleted the second pipeline and added the name swap as a secondary rule under the first pipeline and it began to work. Not sure if that is in the docs but hell if I could find it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [July 2, 2018, 12:57pm UTC](https://community.graylog.org/t/pipeline-source-name-change-not-sticking/5639/3 "2018-07-02T12:57:30Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
