Hi @koshyk ,
i have a small question on this, the above settings will use for source file name right? if i want to extract a index filed extraction in side from source file,?
i changed like this but its not working. can you please take a look.
props.conf
[ms:iis:auto]
TRANSFORMS-raj_namee = test-raj
Transforms.conf
[test-raj]
REGEX = ^(?:[^ \n]* ){2}([^ ]+)
FORMAT = appname::$1
WRITE_META = true
filed.conf
INDEXED=true
and the log format is
2019-07-17 18:21:33 xx-xx.xxx test 10.185.162.2 GET /monitor/monitor.html ----
and i'm using the above regex bold text and it need extract as a appname.
... View more