i have a script which will be executed from inputs.conf but i need the script file name in a new field instead of source tag.
since i have a default source name configured. i want to add script file(source script) Name to the data indexed in the new field.
[script:///$SPLUNK_HOME/etc/apps/KIO/bin/Stats.py] interval = * * * * * source = siebel sourcetype = inflowstats disabled = False index = index1 host=server1 Script=ScriptName
@to4kawa I tried this and not getting any results.
transforms.conf [myeval] INGEST_EVAL = ScriptName=python_script props.conf [testLog] TRANSFORMS = myeval fields.conf [eval_city] INDEXED = True
@to4kawa is this correct to extract from source? i want to extract the file name alone. i want regex for this. please help
SOURCE_KEY = MetaData:Source
FORMAT = job_id::$2
WRITE_META = true
source path will be etc/apps/bin/python.py