Knowledge Management

Extracting the date from a filename without modifying the datetime.xml

mahbs
Path Finder

Hi,

I'm trying to extract the date from a filename without having to configure the config.file, i want to be able to achieve this through the search panel.

This is my file name: name_name_20171130.txt

This is the regular expression I've found that is the closest to helping me achieve what I need:

source="name_name_20171130.txt" host="xxx" |   rex field= source="(?<date>[\d/]+)\s\w+" |table _raw 
ITEM, SOH_DIFF, field

Alternatively, this expression: (?\d{8})

Please Help!

Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi

Can you please try this query, it will extract date from your source file name in date field.

source="name_name_20171130.txt" host="xxx" |   rex field=source "(?:[^\_]*\_){2}(?<date>.*)\.txt" |table _raw, ITEM, SOH_DIFF, date

I hope this helps.

Thanks,
Harshil

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi

Can you please try this query, it will extract date from your source file name in date field.

source="name_name_20171130.txt" host="xxx" |   rex field=source "(?:[^\_]*\_){2}(?<date>.*)\.txt" |table _raw, ITEM, SOH_DIFF, date

I hope this helps.

Thanks,
Harshil

0 Karma

mahbs
Path Finder

Thank you!

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...