Splunk Search
Highlighted

How do I extract farm name from IIS logs to a table?

Path Finder
0 Karma
Highlighted

Re: How do I extract farm name from IIS logs to a table?

Super Champion

@smudge797, Try this:

...|rex field=<fieldname> "https:\/\/([^\/]+\/){3}(?<sites>[^\/]+)"

try this run anywhere search-

| makeresults |eval a="https://sp004.mydomain.net/sites1/spvfvfst/Access%20Requests/pendingreq.aspx..."|rex field=a "https:\/\/([^\/]+\/){3}(?<sites>[^\/]+)"
0 Karma
Highlighted

Re: How do I extract farm name from IIS logs to a table?

hi @smudge797

try this query

 | rex field=<fieldname> "/spvfvfst/(?<MyField>[^,\s]+)/"
0 Karma
Highlighted

Re: How do I extract farm name from IIS logs to a table?

Path Finder

Hi @smudge797, Try this

your base search | rex field=_raw max_match=0 "spvfvfst\/(?<site_name>\S+)\/"
0 Karma