I have a source of /var/log/opscode/desired_sourcetype/current. I need to get the part of the filename that is called "desired_courcetype" via regex. I am almost there, the rewriting is working great. Here is my config:
[chef:server] NO_BINARY_CHECK = true SHOULD_LINEMERGE = false TRANSFORMS-update_metadata = autosource
[autosource] DEST_KEY = MetaData:Sourcetype SOURCE_KEY = MetaData:Source REGEX = \w+ FORMAT = sourcetype::chef:server:$4
Clearly I am not well versed in regex. So woud would the regex be to capture the 3rd element of the filepath delimited by the /.
Any help is MUCH appreciated!
do you want to extract this field at search time or at index time?
at search time you could use a regex like this
test it at https://regex101.com/r/8YMnMh/1