My log directories are structured like so -
/var/myapplogs/<app-name>/logs/*.log
How can I extract <app-name>
as a field name at search time?
In search:
... | rex field=source "^/[^\/]/[^\/]/(?<app_name>[^\/])"
or in props.conf:
[mysourcetype]
EXTRACT-appname = ^/[^\/]/[^\/]/(?<app_name>[^\/]) in source
No. Fields extracted from non-raw indexed fields won't search correctly unless you also configure the extracted field as INDEXED_VALUE = false
in the fields.conf file.
If you go with the props.conf approach, does this then make it possible to do searches on 'appname=fooapp' ?