I have couple of URL 's present in the logs . so I wanted to extract them all into a field ,but when I extract them I am also getting some unwanted data/false url for the field I have extracted . Following is my sample log entry.
1.10.17.6 17.2.3.5 - - [07/Aug/2018:11:3:10 +0000] "POST /search/api/g6/group/get-groupname HTTP/1.1" 200 91 35 33
so from the above log entry the endpoint is /search/api/g6/grp/get-grpname
Take a look at the URL Tool Box or the URL parser in splunkbase
URL Parser
https://splunkbase.splunk.com/app/3396/
URL Toolbox
https://splunkbase.splunk.com/app/2734/