Splunk Search

How to extract fields from multiple file source names?

sfatnass
Contributor

Hi everybody,

I'm trying to extract fields from multiple source names.
It worked for one filename, but I have a lot of files.

It doesn't work with this example :
source::/path/*

if any body can help me thx

0 Karma
1 Solution

rdagan_splunk
Splunk Employee
Splunk Employee

Have you tried this?
[source::/path*/...]
instead of this?
[source::/path/*]

View solution in original post

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

Have you tried this?
[source::/path*/...]
instead of this?
[source::/path/*]

0 Karma

sfatnass
Contributor

i resolve it by using field transform thx

for all reply ^^

0 Karma

somesoni2
Revered Legend

You would need to provide some values, expected result (field names and values that needs to be extracted), and your last attempted search.

0 Karma

sfatnass
Contributor

I will use regex To provide some values.
But how can i do if i have multiple source like 100000 file logs.

0 Karma

somesoni2
Revered Legend

Still not clear to me what you're trying to do here. Do you want to setup a field extraction, in props.conf, for multiple sources? OR you're want to extract a field, from the portion of the source field value?

0 Karma

sfatnass
Contributor

I want To setup a field extraction in props.conf for multiple sources.

0 Karma

somesoni2
Revered Legend

Something like this should work

props.conf on Search Head

[source::/path/*]
EXTRACT-identifier=yourREGEXtoEXTRACTfield

It would be easier to set it up based on sourcetype as it's number should be low. Do these sources report on different sourcetypes?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...