Getting Data In

Extract fields from filename and put it into event

Path Finder

I wang to extract field from event source filename.
The file path format shows:


I want get two fields in my events
such as username=Tom; project=lab1

what should I do ?
How can I confige my props.conf and transforms.conf ,I use SplunkForward to forward my data

0 Karma

Path Finder

You could try this?

EXTRACT-username,project = ^.*?\logs\D+\d_(?[^]+)(?[^_]+) in source

You will need to adjust the regex as I made it pretty quick and it is unlikely to match all the cases you have which you haven't provided.


0 Karma

Super Champion

can you show some sample events to understand better
from your explanation you can try:
in props.conf -

 REPORT-myUniqueClassName = myTransform

in transforms.conf -

  REGEX = (\w+)=(\w+)
  FORMAT = $1::$2
0 Karma