Splunk Search

Filter by URL

roseb
New Member

How do we filter by URL?
I use the search criteria below, however, I'm trying to figure out how will I filter the results by URL (e.g. facebook.com)
eventtype=AllBrowsing user= |table user url

Thanks in advance.

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Add as many filters as you like to your initial search:

eventtype=AllBrowsing user=something url=facebook.com | table user url

That's assuming the entire url value is literally facebook.com, otherwise you'd probably want to extract the host name from the url and filter on that.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Add as many filters as you like to your initial search:

eventtype=AllBrowsing user=something url=facebook.com | table user url

That's assuming the entire url value is literally facebook.com, otherwise you'd probably want to extract the host name from the url and filter on that.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You can add wildcards, e.g. url=facebook.com/*. I highly recommend going through the tutorial at http://docs.splunk.com/Documentation/Splunk/6.6.2/SearchTutorial/WelcometotheSearchTutorial

There is endless information in the docs, including how to work with fields: http://docs.splunk.com/Documentation/Splunk/6.6.2/Knowledge/Aboutfields

0 Karma

roseb
New Member

Hi Martin,

Thanks for your thorough answer.

The url value is not exactly facebook.com. It could be anything after the url like "facebook.com/posts/123"
Can I add a wildcard entry like url=facebook.com/* or how do I do your recommendation "extract the host name from the url and filter on that"?

🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...