I have a log File as follows
07:30:57.222 02/20/2017 File "SKU_DR2_DBF_FULL_20170220_122856.csv" is received from FTP server "209.55.186.211"
Now, I need to extract the file name as SKU_DR2_DBF_FULL_20170220_122856 except the .csv Someone please help me on this.
Instead of this I have worked with IFX in Splunk
Try this:
| rex field=_raw "File\s\"(?P<file>.[^\"]*)"
I thought the same thing, but see OPs "expected output is..."
richgalloway's answer is correct for that expected output.
Oops. I didn't see he didn't want the file extension 😛
Expected Output is:
File
SKU_DR2_DBF_FULL_20170220_122856
Try this
... | rex "File \"(?<file>[^\.]+)" | ...