Hi team,
I have some directory paths as below
path arrival_time
home*/vivek/file1.txt* 12:30:00 05-05-2019
home*/pench/file2.txt* 01:00:00 05-05-2019
i just want to read the highlighted values from path field and the arrival_time details from the data not the content of the files through Splunk.
Can you please let me know how can i achieve this.
([\w|\d]+\/[\w|\d]+\.[\w|\d]+)
adding the sample data to avoid confusion
path arrival_time
home/vivek/file1.txt 12:30:00 05-05-2019
home/pench/file2.txt 01:00:00 05-05-2019
@jkat54 @vnravikumar @woodxo any solution to this?