Hi all,
I have a file that looks like this -
Added files:
added: /etc/addedthisfile
added: /etc/cron.daily/tripwire-check
added: /etc/tripwire
How can field extract added=*?
In search you can do like this (in-line field extraction: extracting field 'Files' as multivalued field which contains all paths)
your base search | rex max_match=0 "added: (?<Files>\S+)"
To do that automatically (saved field extraction), you can follow this
https://docs.splunk.com/Documentation/Splunk/7.0.3/Knowledge/ConfigureSplunktoparsemulti-valuefields
OR
https://docs.splunk.com/Documentation/Splunk/7.0.3/Knowledge/Exampleconfigurationsusingfieldtransfor...
In search you can do like this (in-line field extraction: extracting field 'Files' as multivalued field which contains all paths)
your base search | rex max_match=0 "added: (?<Files>\S+)"
To do that automatically (saved field extraction), you can follow this
https://docs.splunk.com/Documentation/Splunk/7.0.3/Knowledge/ConfigureSplunktoparsemulti-valuefields
OR
https://docs.splunk.com/Documentation/Splunk/7.0.3/Knowledge/Exampleconfigurationsusingfieldtransfor...