Splunk Search

Extract all the URl's present in the log into a field and count number of times each url is called .

navd
New Member

I have couple of URL 's present in the logs . so I wanted to extract them all into a field ,but when I extract them I am also getting some unwanted data/false url for the field I have extracted . Following is my sample log entry.

1.10.17.6 17.2.3.5 - - [07/Aug/2018:11:3:10 +0000] "POST /search/api/g6/group/get-groupname HTTP/1.1" 200 91 35 33

so from the above log entry the endpoint is /search/api/g6/grp/get-grpname

Tags (1)
0 Karma

dcharboneau_spl
Splunk Employee
Splunk Employee

Take a look at the URL Tool Box or the URL parser in splunkbase
URL Parser
https://splunkbase.splunk.com/app/3396/

URL Toolbox
https://splunkbase.splunk.com/app/2734/

0 Karma
Get Updates on the Splunk Community!

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...