Hi, I would to know if it is possible to use a part of the source events file path ie "foobar" from
and extract it as a field or value (ie ws_server) in either a search or via transforms.conf / props.
For using it in a search, you can test it with this:
rex field=_raw "https-blah.com/(?<path>\S*)"
Might have to adjust it, depending on what other values exist.
After that, use field extractions.
Yes you can extract it to a field. If you want to search for it, you will want to use a indexed field (as opposed to a search time extracted field).
SOURCE_KEY = MetaData:Source REGEX = /([^/]+)$ FORMAT = ws_server::$1 WRITE_META = true
[ws_server] INDEXED = true INDEXED_VALUE = false
Extracting a search-time field would be easier. Just specifing the extraction in props.conf:
[your_sourcetype] EXTRACt-ws = ^/([^/]+)$ in source