Splunk Search

How can I extract address from string?

Annieg
Observer

I have the following string:

SL=5601%20BLVD%20E%2C%20WESTON%20NEW%20YORK%2C%20NJ%20%2007093%20(WEST%20NEW%20YORK%20TOWN%2C%20HUDS...

I want to extract the address from this. I have tried regex with %20 and split but nothing works. 

Labels (2)
Tags (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Use urldecode(). Like this:

| makeresults 
| eval a="SL=5601%20BLVD%20E%2C%20WESTON%20NEW%20YORK%2C%20NJ%20%2007093%20(WEST%20NEW%20YORK%20TOWN%2C%20HUDS"
| eval b=urldecode(a)

BTW, you pasted whole URL to your Splunk environment. You should be more careful. Next time it might contain sensitive info.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...