Splunk Search

How can I extract additional fields from this source?

New Member

eg:
source = shuttle(Oct1-3).zip:./shuttle/5720/LOG/shuttlelog.20171002 ,shuttle3.zip:./shuttle3/5720/LOG/shuttlelog.20171011....etc
I want to extract folder _no : 5720

If possible please tell the regex expression to extract the fields
Pls help me.

Thanks

0 Karma

Super Champion

Have a try regex of (Based on 5720 being the 2nd occurence in /)

(?:\/(.+?)){2}\/

https://regex101.com/r/kOJR7y/1