Reporting

How to combine multiple uri_paths in a report to show data for the single corresponding application?

SaiKalyani
Engager

Hi All
Suppose i have different uri_paths for single application X
ex : /abc/xyz/, 123/abc/, xyz/wer/*
i want to show a report in which i can say for all of these uri_paths it should show me the data as Application name X

Tags (4)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could define a tag on that field and store all the valid values for application X under one tag value. Then you can search for tag::uri_path=application_X.
Alternatively, you could define a lookup that maps URIs to applications, add that lookup to your data, and then use that lookup field as your classification.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...