I am trying to write a splunk query to create a dashboard.
I have message from where I need particular part as filename
"Copying the file : /mount/logs/output/fileName.xml to : /mount/splunk/fileName.xml.pgp is started"
I need the part fileName.xml.pgp from the above message, how do I achieve this?
Thanks
try this:
index=<your_index> | rex "\/splunk\/(?<filename>[^\s]+)"
If it's not working then please give more sample inputs. This solution is on the assumption that it always follows the path /splunk/filename
rex
to the rescue!
... | rex "to\s:\s.*\/(<filename>\S+)"