Splunk Dev

remove path from source to only show file name for file monitor input

Skins
Path Finder

Is there a way at input time to omit the path of the file monitor to leave only the file names ?

path monitored :

/opt/csv/*

in the location - the files ..

filenameA.csv
filenameB.csv
filenameC.csv
filenameD.csv

but the source is alway prepended with the path.

/opt/csv/filenameA.csv
/opt/csv/filenameB.csv

can this be removed at input ?

gratzi

Tags (1)
0 Karma

vishaltaneja070
Motivator

Hello @Skins,

This can be done at Parsing time using transforms.conf
[replacedefaultsource]
SOURCE_KEY = MetaData:Source
REGEX = \/opt\/csv\/(\w+.\w+)
DEST_KEY = MetaData:Source
FORMAT= source::$1

0 Karma

Skins
Path Finder

tried this exactly as above in transforms.conf and had no effect

splunk was restarted.

0 Karma

vishaltaneja070
Motivator

did you call it through props.conf?

Like:
[your_sourcetype]
TRANSFORMS-sourcename= replacedefaultsource

0 Karma
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...