Hi!
temp=C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe
to...
path=C:\Program Files\SplunkUniversalForwarder\bin
process=splunk-powershell.exe
this is what I reach...
I'm stuck at the regex.
Any other method is also appreciated
| rex field=temp "(?[^\\\/]*)$" |regex path=!temp |table FILENAME,PATH
(pls check this.. very manual rex,..
| makeresults
| eval temp="C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"
| rex field=temp "(?P<path>\w+\W+\w+\W\w+\W\w+\W\w+\W)(?P<fileName>\w+\W\w+\W\w+)"
| table path fileName
PS - if it resolves your task, pls accept this as answer
(pls check this.. very manual rex,..
| makeresults
| eval temp="C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"
| rex field=temp "(?P<path>\w+\W+\w+\W\w+\W\w+\W\w+\W)(?P<fileName>\w+\W\w+\W\w+)"
| table path fileName
PS - if it resolves your task, pls accept this as answer
Try this:
(?<path>.*)\\(?<file>[^\\]*)$