Splunk Search

How can I improve my regular expression to extract a field located inside a URL?

guillecasco
Path Finder

Hey i have the following logs:

INCOMING REQUEST:
URL:  /pop/v1/enviro/2ee999b4-d97ba81bdefd/updatesearching/

i need to extract the numbers after enviro/ and before /updatesearching

i created following regular expression: REX "URL:\s\/\w+\/\w+\/\enviro/(?.*)/updatesearching/

but i'm not getting it. how can i improve the regular expression or how can i extract that number?

0 Karma
1 Solution

gokadroid
Motivator

Can you please try this and see if it works for you:

If it's always between enviro and updatesearching:

your query to return events
|rex field=_raw "enviro\/(?<capturedNum>[^\/]+)\/updatesearching"
| table capturedNum

If the numbers of interest come always after enviro:

your query to return events
|rex field=_raw "\/enviro\/(?<capturedNum>[^\/]+)\/"
| table capturedNum

If it's always the fourth element then try this:

your query to return events
|rex field=_raw "URL:\s*\/([^\s\/]+\/){3}(?<capturedNum>[^\/]+)\/"
| table capturedNum

View solution in original post

gokadroid
Motivator

Can you please try this and see if it works for you:

If it's always between enviro and updatesearching:

your query to return events
|rex field=_raw "enviro\/(?<capturedNum>[^\/]+)\/updatesearching"
| table capturedNum

If the numbers of interest come always after enviro:

your query to return events
|rex field=_raw "\/enviro\/(?<capturedNum>[^\/]+)\/"
| table capturedNum

If it's always the fourth element then try this:

your query to return events
|rex field=_raw "URL:\s*\/([^\s\/]+\/){3}(?<capturedNum>[^\/]+)\/"
| table capturedNum

guillecasco
Path Finder

it worked! |rex field=_raw "enviro\/(?[^\/]+)\/updatesearching" thanks dude

0 Karma

guillecasco
Path Finder

what is the field=_raw does exactly. I didnt put there anything

0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...