Splunk Search

Extract all the URl's present in the log into a field and count number of times each url is called .

navd
New Member

I have couple of URL 's present in the logs . so I wanted to extract them all into a field ,but when I extract them I am also getting some unwanted data/false url for the field I have extracted . Following is my sample log entry.

1.10.17.6 17.2.3.5 - - [07/Aug/2018:11:3:10 +0000] "POST /search/api/g6/group/get-groupname HTTP/1.1" 200 91 35 33

so from the above log entry the endpoint is /search/api/g6/grp/get-grpname

Tags (1)
0 Karma

dcharboneau_spl
Splunk Employee
Splunk Employee

Take a look at the URL Tool Box or the URL parser in splunkbase
URL Parser
https://splunkbase.splunk.com/app/3396/

URL Toolbox
https://splunkbase.splunk.com/app/2734/

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...