Splunk Search

Find last value of multivalue field (Split and mvindex)

New Member

I have a URL field and need to find the last word (split by "/")

Ex:
URL 1: xxx/yyy/ServiceName
URL 2 : aaa/bbb/ccc/ddd/serviceName

I tried mvindex(split(URL, "/"),5) to get the service name, but the index "5" shouldn't be static, number of sub folders vary from URL to URL. Need help in identifying the last index on the URL.

Thanks in advance.

Tags (3)
0 Karma
1 Solution

Motivator

You can count from the end by using negative values. mvindex(split(URL,"/"),-1) will get you what you want.

View solution in original post

Motivator

You can count from the end by using negative values. mvindex(split(URL,"/"),-1) will get you what you want.

View solution in original post

New Member

Thank you!

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!