Splunk Search

Extract fields from an already extracted field

I'm trying to extract the filename and file ext of a windows path into to different fields. The sourcetype is CSV and the path is already extracted into a field called Threat Target File Path.

The event looks like:

10/30/15 8:01:40 AM,Z4437-E6A5-58E3,,C:\Users\u106420\Videos\WP_20140610_002.mp4,NT AUTHORITY\SYSTEM,C:\Windows\system32\svchost.exe

The field Threat Target File Path contains:


And I would like:

Threat Target File Name = WP_20140610_002
Threat Target File Ext = mp4

I would like 'automate' this so I'm guessing that i need to add entries into the transforms.conf and props.conf,

Is this possible and what entries would I need to get the two additional field extractions?

Try this:

Inside props.conf:

REPORT-this_part_does_not_matter_but_must_come_below_whatever_created_Threat_Target_File_Path = filename_into_two_parts

Inside transforms.conf:

SOURCE_KEY="Threat Target File Path"
@markwymer

10/30/15 8:01:40 AM,Z4437-E6A5-58E3,,C:\Users\u112200\Videos\WP_20140610_002.mp4,NT AUTHORITY\SYSTEM,C:\Windows\system32\svchost.exe

and the "Threat Target File Path" is


