<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic erex command not working for URL fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/erex-command-not-working-for-URL-fields/m-p/218055#M176597</link>
    <description>&lt;P&gt;I am using Splunk 6.4. &lt;BR /&gt;
I am able to extract many fields from my data using erex comand. However, for URL fields, the erex comamand doesnt work.&lt;/P&gt;

&lt;P&gt;My events-&lt;BR /&gt;
1470993728.300 44 81.11.191.113 TCP_REFRESH_HIT/200 9403 GET &lt;A href="http://www.fastcompany.com/files/imagecache/rs_145_image/files/gadgets5.jpg" target="_blank"&gt;http://www.fastcompany.com/files/imagecache/rs_145_image/files/gadgets5.jpg&lt;/A&gt; &lt;A href="mailto:emaxwell@buttercupgames.com" target="_blank"&gt;emaxwell@buttercupgames.com&lt;/A&gt; DIRECT/&lt;A href="http://www.fastcompany.com" target="_blank"&gt;www.fastcompany.com&lt;/A&gt; image/jpeg DEFAULT_CASE-DefaultGroup-Demo_Clients-NONE-NONE-DefaultRouting  - &lt;A href="http://www.fastcompany.com/" target="_blank"&gt;http://www.fastcompany.com/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;1470947922.609 85 147.213.138.201 TCP_REFRESH_HIT/200 1801 GET &lt;A href="http://www.educationworld.com/images2/home/homepage_section_profdev.gif" target="_blank"&gt;http://www.educationworld.com/images2/home/homepage_section_profdev.gif&lt;/A&gt; &lt;A href="mailto:bhussain@buttercupgames.com" target="_blank"&gt;bhussain@buttercupgames.com&lt;/A&gt; DIRECT/&lt;A href="http://www.educationworld.com" target="_blank"&gt;www.educationworld.com&lt;/A&gt; - ALLOW_WBRS-DefaultGroup-Demo_Clients-NONE-NONE-DefaultRouting  - &lt;A href="http://www.educationworld.com/" target="_blank"&gt;http://www.educationworld.com/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I am using the below command -&lt;BR /&gt;
index="main" | erex domain1 examples="&lt;A href="http://www.fastcompany.com/,http://www.educationworld.com/,http://www.lowermybills.com/,http://www.fftoday.com/,http://www.adventureindonesia.com/,http://www.puffpastry.com/," target="_blank"&gt;http://www.fastcompany.com/,http://www.educationworld.com/,http://www.lowermybills.com/,http://www.fftoday.com/,http://www.adventureindonesia.com/,http://www.puffpastry.com/,&lt;/A&gt;" | dedup domain1 | table domain1&lt;/P&gt;

&lt;P&gt;This does not give any result.&lt;BR /&gt;
Is this because of / characters in the URL ? How to solve this ?&lt;BR /&gt;
Please suggest. &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 11:12:01 GMT</pubDate>
    <dc:creator>Upas02</dc:creator>
    <dc:date>2020-09-29T11:12:01Z</dc:date>
    <item>
      <title>erex command not working for URL fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/erex-command-not-working-for-URL-fields/m-p/218055#M176597</link>
      <description>&lt;P&gt;I am using Splunk 6.4. &lt;BR /&gt;
I am able to extract many fields from my data using erex comand. However, for URL fields, the erex comamand doesnt work.&lt;/P&gt;

&lt;P&gt;My events-&lt;BR /&gt;
1470993728.300 44 81.11.191.113 TCP_REFRESH_HIT/200 9403 GET &lt;A href="http://www.fastcompany.com/files/imagecache/rs_145_image/files/gadgets5.jpg" target="_blank"&gt;http://www.fastcompany.com/files/imagecache/rs_145_image/files/gadgets5.jpg&lt;/A&gt; &lt;A href="mailto:emaxwell@buttercupgames.com" target="_blank"&gt;emaxwell@buttercupgames.com&lt;/A&gt; DIRECT/&lt;A href="http://www.fastcompany.com" target="_blank"&gt;www.fastcompany.com&lt;/A&gt; image/jpeg DEFAULT_CASE-DefaultGroup-Demo_Clients-NONE-NONE-DefaultRouting  - &lt;A href="http://www.fastcompany.com/" target="_blank"&gt;http://www.fastcompany.com/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;1470947922.609 85 147.213.138.201 TCP_REFRESH_HIT/200 1801 GET &lt;A href="http://www.educationworld.com/images2/home/homepage_section_profdev.gif" target="_blank"&gt;http://www.educationworld.com/images2/home/homepage_section_profdev.gif&lt;/A&gt; &lt;A href="mailto:bhussain@buttercupgames.com" target="_blank"&gt;bhussain@buttercupgames.com&lt;/A&gt; DIRECT/&lt;A href="http://www.educationworld.com" target="_blank"&gt;www.educationworld.com&lt;/A&gt; - ALLOW_WBRS-DefaultGroup-Demo_Clients-NONE-NONE-DefaultRouting  - &lt;A href="http://www.educationworld.com/" target="_blank"&gt;http://www.educationworld.com/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I am using the below command -&lt;BR /&gt;
index="main" | erex domain1 examples="&lt;A href="http://www.fastcompany.com/,http://www.educationworld.com/,http://www.lowermybills.com/,http://www.fftoday.com/,http://www.adventureindonesia.com/,http://www.puffpastry.com/," target="_blank"&gt;http://www.fastcompany.com/,http://www.educationworld.com/,http://www.lowermybills.com/,http://www.fftoday.com/,http://www.adventureindonesia.com/,http://www.puffpastry.com/,&lt;/A&gt;" | dedup domain1 | table domain1&lt;/P&gt;

&lt;P&gt;This does not give any result.&lt;BR /&gt;
Is this because of / characters in the URL ? How to solve this ?&lt;BR /&gt;
Please suggest. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:12:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/erex-command-not-working-for-URL-fields/m-p/218055#M176597</guid>
      <dc:creator>Upas02</dc:creator>
      <dc:date>2020-09-29T11:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: erex command not working for URL fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/erex-command-not-working-for-URL-fields/m-p/218056#M176598</link>
      <description>&lt;P&gt;I took your events and ran the query and I'm getting the results. Check this run anywhere sample.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| gentimes start=-1 | eval raw="1470993728.300 44 81.11.191.113 TCP_REFRESH_HIT/200 9403 GET &lt;A href="http://www.fastcompany.com/files/imagecache/rs_145_image/files/gadgets5.jpg" target="test_blank"&gt;http://www.fastcompany.com/files/imagecache/rs_145_image/files/gadgets5.jpg&lt;/A&gt; emaxwell@buttercupgames.com DIRECT/www.fastcompany.com image/jpeg DEFAULT_CASE-DefaultGroup-Demo_Clients-NONE-NONE-DefaultRouting - &lt;A href="http://www.fastcompany.com/&amp;quot;" target="test_blank"&gt;http://www.fastcompany.com/"&lt;/A&gt;;  | rename raw as _raw | append [ | gentimes start=-1 | eval raw="1470947922.609 85 147.213.138.201 TCP_REFRESH_HIT/200 1801 GET &lt;A href="http://www.educationworld.com/images2/home/homepage_section_profdev.gif" target="test_blank"&gt;http://www.educationworld.com/images2/home/homepage_section_profdev.gif&lt;/A&gt; bhussain@buttercupgames.com DIRECT/www.educationworld.com - ALLOW_WBRS-DefaultGroup-Demo_Clients-NONE-NONE-DefaultRouting - &lt;A href="http://www.educationworld.com/&amp;quot;" target="test_blank"&gt;http://www.educationworld.com/"&lt;/A&gt;;  | rename raw as _raw ] | erex domain1 examples="http://www.fastcompany.com/,http://www.educationworld.com/,http://www.lowermybills.com/,http://www.fftoday.com/,http://www.adventureindonesia.com/,http://www.puffpastry.com/" | dedup domain1 | table domain1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 30 Sep 2016 15:44:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/erex-command-not-working-for-URL-fields/m-p/218056#M176598</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-09-30T15:44:40Z</dc:date>
    </item>
  </channel>
</rss>

