Splunk Search

Extracting filename from verbose message

gravi
Explorer

I am trying to write a splunk query to create a dashboard.

I have message from where I need particular part as filename

"Copying the file : /mount/logs/output/fileName.xml to : /mount/splunk/fileName.xml.pgp is started"

I need the part fileName.xml.pgp from the above message, how do I achieve this?

Thanks

0 Karma

mayurr98
Super Champion

try this:

index=<your_index> | rex "\/splunk\/(?<filename>[^\s]+)"

If it's not working then please give more sample inputs. This solution is on the assumption that it always follows the path /splunk/filename

0 Karma

richgalloway
SplunkTrust
SplunkTrust

rex to the rescue!

... | rex "to\s:\s.*\/(<filename>\S+)"
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...