I have some old syslog files to index.
I'm trying to extract year from the filename and month, day, time from events (in a custom datetime.xml) without success.
Is it possible? How to do that?
Thanks
@C_HIEN
check that filename and source field have same value. If so you can extract by using regex or field extraction
1) rex field=source "/tmp/filename-(?<fileyear>\d+)"
2) props.conf
EXTRACT-fileyear = /tmp/filename-(?<fileyear>\d+) in source
Thanks for your answer. I've already seen the answers you mention but it's not exactly what i'm trying to do... I want extract the year only from filename and get day and month from events... I've temporary solved my problem with an uf on a virtual machine within the system date was changed to the year of the files to index. But i still hope there is a better solution...
Sorry, I missed the "day, time from events" portion of the question. I think "sbbadri" has the piece you're looking for. Good luck!