I need to extract part of a uri and store this string in a field to run statistics on it.
I don't know if it's possible, but if it is, then please let me know how I can extract this part of the uri and run statistics on it! Thank you
Ps: I intentionally made error in the links because i dont have enough karma to post links
based on your provided events you can try something like this:
your base search here | rex "\/(?<myURI>\w+)\/" | stats count by myURI
If this is what you're looking for, setup the regex as automatic field extraction - read more about this in the docs http://docs.splunk.com/Documentation/Splunk/6.2.2/Knowledge/ExtractfieldsinteractivelywithIFX
Hope this helps ...
If you have your sourcetype as accesscombinedwcookie or access_common, Splunk automatically extracts that URI segment as a field called "root".