Splunk Search

Exclude path from URL in Search Results

spfingst87
Loves-to-Learn

Hi

I want to exclude the path from search results, i.e.:

www.testsite.com

www.testsite.com/path1

www.testsite.com/path2

www.testsite.com/path3

www.secondsite.com

www.secondsite.com/path1

 

From the above, all the sites are displaying in my search. I only want www.testsite.com and www.secondsite.com to show in search and rest of sites to be excluded.

Thanks.

Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| regex _raw!="/"

Replace _raw with your field name if appropriate

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There probably are a few ways to do that.  I'd use rex to extract the site from the URL.

... | rex field=url "(?<site>[^\/]+)"

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

spfingst87
Loves-to-Learn

Thanks for the fast response 🙂

I tried this and still the search is producing URL paths. In the site, do I need to put a variable?

As a note, there are around 50 URLs in my search and around 10 of them are displaying several paths each. So I am looking for as universal solution for any current or future URLs added to exclude the path (if that makes any sense :)) not just for 1 specific URL.

Thanks again!

0 Karma

bowesmana
SplunkTrust
SplunkTrust

The suggested solution was for a field called url and it will extract a new field called site.

Depending on your data, replace 'url' with your input field and use the new field site for your analysis

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...