I'm having issues creating a custom field extraction based on the source field. Here's all the information.
inputs.conf - Heavy Forwarder
disabled = 0
index = test
sourcetype = Support:TS2
props.conf - Search Head (metadata [props] export=system)
EXTRACT-custom_extracted_field = /mnt/splunkLogShare/(TS1|TS2|TS3|TS4|TS5)/(?<custom_extracted_field>[^/]+)/.* in source
Directory structure - Heavy Forwarder
Searching for the following returns nothing as custom_extracted_field doesn't exist
Searching the following creates custom_extracted_field without issue
index=test source=\*300-222222\* | rex field=source "/mnt/splunkLogShare/(TS1|TS2|TS3|TS4|TS5)/(?[^/]+)/.*"
No automatic field extraction is happening. Thoughts?
Worked with hortonew via IRC. Looks like it was just a bad props spec 🙂
Edit: You still cannot do wildcards like * for sourcetype specs in props 😞
View solution in original post
Seems you can't add a sourcetype spec with a wildcard. Added each sourcetype individually and it started working. e.g.: