Splunk Search

Extracting a field thats not recognized

venkatachalamvi
New Member

My rawdata from log is below

METHOD="POST" URI="CALLOUT-LOG" USER_ID_DERIVED="00532000004sefcAAA" EVENT_TYPE="ApexCallout" TYPE="REST" CLIENT_IP="" URL=""https://api.contact.com/ContactAuthorizationServer/Token"" RUN_TIME="532" SESSION_KEY="" TIMESTAMP="20200529045947.928" REQUEST_SIZE="76" LOGIN_KEY="" REQUEST_ID="4WCb1_2dhf_Zn9-qbvXjs-"

alt text

Splunk assumes URL as "" since URL value is passed to index in 2 double quotes.

I used eval to parse out and get the actual URL to a field in search as URLX but the field URLX becomes jumbled if I use like stats count by URLX.

my eval is eval ..... URLX=replace(_raw, ".URL=\"\"(.)\"\" RUN_TIME.*", "\1"), "/")

How do I properly tell splunk to get URL extracted without eval in the first place.

Thanks fpr help in advance.

Labels (2)
0 Karma
1 Solution

493669
Super Champion

You may want to use rex to extract url-

...|rex field=URL "\"(?<URL>[^\"]+)"

View solution in original post

0 Karma

venkatachalamvi
New Member

I eventually got it using this below

".*URL=\"\"(?P<urlx>.*)\"\" .*" 

Thank you for the responses.

0 Karma

493669
Super Champion

You may want to use rex to extract url-

...|rex field=URL "\"(?<URL>[^\"]+)"
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...