Splunk Search

field extraction on specific path

Explorer

Hi
I have some log files with different name that copy into the Splunk server "/opt/splunk/logs" daily.
when I extract fields it just do this on specific file, while I need those field extract on every log on that path.
what is the solution here? I should define index for all logs and the extract field? is there any idea?

Thanks,

0 Karma

Esteemed Legend

You can use this in props.conf:

[source:///Your/Partial/Path/Here/*]
Your Settings Here
0 Karma