I am trying to write a splunk query to create a dashboard.
I have message from where I need particular part as filename
"**Copying the file : /mount/logs/output/fileName.xml to : /mount/splunk/fileName.xml.pgp is started**"
I need the part **fileName.xml.pgp** from the above message, how do I achieve this?
Thanks
↧