Hello all,
I have the following string:
"6900 0 1024 0 0 0 0 0 0 0 C:\windows\System32\Launcher.exe "C:\windows\System32\Launcher.exe" "C:\Folder\Link - Shortcut.lnk" ",
And I need a way to get the very last part (e.g.. Shortcut.lnk). Normally I would use regex for this in SQL or code, but for the life of me, I can't figure out how to implement it in Splunk.
Any help is greatly appreciated..
Splunk does regex, too. Assuming your text is already extracted, this should pull out the last part. I've made other assumptions about the characters that start and end the desired text so you may need to adjust the regex.
... | rex field=text "- (?<shortcut>[^\"]*)" | ...
Can you provide a few more samples?