I need to extract the name of the computer generating the log from the file name. I found a way to do so with rex:
index=* | rex field=source ".(?<Chassis>C\d+)"
That works as it should, but the field is only present for the search creating the field.
So I thought I need to extract the field in my props.conf in order to make them permanent.
What I tried and what I found here on Splunk Answers did not work. I guess it has something to do with extracting a field from the source field.
Here is what I tried:
[RT-VPM] EXTRACT-Chassis = C\d+ in source
[RT-VPM] EXTRACT-Chassis = .(?<Chassis>C\d+) in source
I also tried quite a few variations on 1 and 2, but I did not document all of them.
I hope somebody is able to help me
You need to use a transform where you have a different source field:
# props.conf [RT-VPM] REPORT-chassis = chassis # transforms.conf [chassis] SOURCE_KEY=source REGEX = .(?<Chassis>C\d+)
could this work on lookup output fields also ?? and what will be the solution if not?