I have data in los as specified in below sample.
As mentioned in http://docs.splunk.com/Documentation/Splunk/6.0/Data/Extractfieldsfromfileheadersatindextime
I tried to extarat field values directly from header.
I used the below configuration in props.conf:
CHECK_FOR_HEADER = true
FIELD_DELIMITER = \|\^
INDEXED_EXTRACTIONS = PSV
PREAMBLE_REGEX = FILEHEADER.*
FIELD_HEADER_REGEX = @FIELDS\|\^
SHOULD_LINEMERGE = false
But doesn't seem to work, can anyone help please??
Field header regex requires a capture group for the text that contains the fields like below:
FIELD_HEADER_REGEX = @FIELDS(.*)
your FIELD_HEADER_REGEX looks not okay, it should be like this:
the expression is pur regex in FIELD_HEADER_REGEX option, so your ^ was handled as regex command which means Matches the beginning of the string
Matches the beginning of the string
oh was that there before? 🙂 well, yes it should. You could test it if you just use @FIELDS and double check the sourcetype that it matches.
MuS, i escaped the caret rite..so it will take it a literal ^ and not start of line rite??