Grok - extract file extension from file name

(evild3ad) #1


I have problems with creating a grok filter to extract the file extension from the file name field.

Example data:
80bddb9998f9f66bc44b59d9899bbbb853b8958ecd9188e14fd0828e00246050.txt ($FILE_NAME)

I tried:

But I don't want to have "($FILE_NAME)"...only the file extension.


(evild3ad) #2


(evild3ad) #3

Hm...but here is it still not working:

Apps - Process All.pas.0001.bak

Any idea?

(Magnus B├Ąck) #4

Make sure you escape the period and add a $ anchor at the end so you only match alphanumerical sequences at the end of the string.

(system) #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.