I have a field in my Splunk search name filepath which contains the base path of file like below
repository/2650/document/960891_1.pdf
repository/357/document/96_1.wordx
I need to extract below string from my already existing field.
filepath value : repository/2650/document/960891_1.pdf
extract value : repository/2650/document/960891_1
filepath value : repository/357/document/96_1.wordx
extract value : repository/357/document/96_1
in short, I need to remove file extension from field value dynamically
@paragvidhi ,
Try
| rex field=filepath "(?<Base>.+)\.[^.]+$"
where filepath
is your current field
@paragvidhi ,
Try
| rex field=filepath "(?<Base>.+)\.[^.]+$"
where filepath
is your current field
@renjith.nair ,
Thanks for your help it's working for me
thanks a lot