Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Field transformation on source not working

$
0
0
Hi There, There is no content in dummy field although the regex works fine. Please could you help me with this? Type: Regex-based Regular expression: "(\/\w+){2}\/(?.*?)\/" Tried "(\/\w+){2}\/(?.*?)\/" in source Source Key: source Checked create multi valued fields. same source field content is as below: /folder1/folder2/SAMPLE1/Test.log /folder1/folder2/SAMPLE2/Test.log

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>