I have a file that Splunk monitors stored in F:/xxx/2014/file.csv. Is there any way to dynamically take the 2014 folder and assign the 2014 value to a "report_year" field for each event? (Folder may be any year, not just 2014)
Yes, use the rex command with the "source" as the field. Like so:
<base search> | rex field=source "(.*/){2}(?P<year>\d+)/"
This will dinamically look for the second forward slash "/" and then capture all digits in a field labeled year.
Hope this helps