I wang to extract field from event source filename.
The file path format shows:
I want get two fields in my events
such as username=Tom; project=lab1
what should I do ?
How can I confige my props.conf and transforms.conf ,I use SplunkForward to forward my data
You could try this?
EXTRACT-username,project = ^.*?\logs\D+\d_(?[^]+)(?[^_]+) in source
You will need to adjust the regex as I made it pretty quick and it is unlikely to match all the cases you have which you haven't provided.
can you show some sample events to understand better
from your explanation you can try:
in props.conf -
REPORT-myUniqueClassName = myTransform
in transforms.conf -
REGEX = (\w+)=(\w+)
FORMAT = $1::$2