Splunk Search

field extraction on specific path


I have some log files with different name that copy into the Splunk server "/opt/splunk/logs" daily.
when I extract fields it just do this on specific file, while I need those field extract on every log on that path.
what is the solution here? I should define index for all logs and the extract field? is there any idea?


0 Karma

Esteemed Legend

You can use this in props.conf:

Your Settings Here
0 Karma