Splunk Search

How to extract fields from multiple file source names?

sfatnass
Contributor

Hi everybody,

I'm trying to extract fields from multiple source names.
It worked for one filename, but I have a lot of files.

It doesn't work with this example :
source::/path/*

if any body can help me thx

0 Karma
1 Solution

rdagan_splunk
Splunk Employee
Splunk Employee

Have you tried this?
[source::/path*/...]
instead of this?
[source::/path/*]

View solution in original post

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

Have you tried this?
[source::/path*/...]
instead of this?
[source::/path/*]

0 Karma

sfatnass
Contributor

i resolve it by using field transform thx

for all reply ^^

0 Karma

somesoni2
Revered Legend

You would need to provide some values, expected result (field names and values that needs to be extracted), and your last attempted search.

0 Karma

sfatnass
Contributor

I will use regex To provide some values.
But how can i do if i have multiple source like 100000 file logs.

0 Karma

somesoni2
Revered Legend

Still not clear to me what you're trying to do here. Do you want to setup a field extraction, in props.conf, for multiple sources? OR you're want to extract a field, from the portion of the source field value?

0 Karma

sfatnass
Contributor

I want To setup a field extraction in props.conf for multiple sources.

0 Karma

somesoni2
Revered Legend

Something like this should work

props.conf on Search Head

[source::/path/*]
EXTRACT-identifier=yourREGEXtoEXTRACTfield

It would be easier to set it up based on sourcetype as it's number should be low. Do these sources report on different sourcetypes?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...