Splunk Dev

remove path from source to only show file name for file monitor input

Skins
Path Finder

Is there a way at input time to omit the path of the file monitor to leave only the file names ?

path monitored :

/opt/csv/*

in the location - the files ..

filenameA.csv
filenameB.csv
filenameC.csv
filenameD.csv

but the source is alway prepended with the path.

/opt/csv/filenameA.csv
/opt/csv/filenameB.csv

can this be removed at input ?

gratzi

Tags (1)
0 Karma

vishaltaneja070
Motivator

Hello @Skins,

This can be done at Parsing time using transforms.conf
[replacedefaultsource]
SOURCE_KEY = MetaData:Source
REGEX = \/opt\/csv\/(\w+.\w+)
DEST_KEY = MetaData:Source
FORMAT= source::$1

0 Karma

Skins
Path Finder

tried this exactly as above in transforms.conf and had no effect

splunk was restarted.

0 Karma

vishaltaneja070
Motivator

did you call it through props.conf?

Like:
[your_sourcetype]
TRANSFORMS-sourcename= replacedefaultsource

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...