Splunk Search

Combination of uri patterns

xvxt006
Contributor

Hi,

i would like to capture the below 2 patterns and i tried to use the below combination but i am not getting intended results. Can someone help

/product/Dsdhty-wetds-Cartridge-3456er?s_pp=false

/search?searchQuery=1DAH1

Tried this..
| (uri=/product/* OR regex uri="/search\?searchQuery=\w{5}$")

Tags (1)
0 Karma

lukejadamec
Super Champion

You're missing a slash before the w.

\w{5}$

Well, I don't think you can use an OR with a regex, and a subsearch won't work. You can append the results. Here is an example for pulling two series of EventCodes.

index=main EventCode="5*" |stats count by EventCode |append [search index=main EventCode="*" | regex EventCode="^4\d+" |stats count by EventCode]
0 Karma

lukejadamec
Super Champion

I updated the answer with an example of append.

0 Karma

lukejadamec
Super Champion

Highlight the string and click the 101010 format option to capture the special characters.

0 Karma

xvxt006
Contributor

Actually for some reason it is not showing the backslash when i put it but i do have it in my query 🙂

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...