Splunk Search

How should i do SEDCMD filter URL?

chengyu
Path Finder

I have use Heave Forward and modify props.conf

source:...

SEDCMD-nourl = s/\surl=("\w+"|"\w+\[./\]"|)\s/ /g    

RAW data:
i.g:

url="N/A" -----OK

or

url="/bases/av/kdb/i386/kdb-i386-1211g.xml.dif" ----Fail

or

url="/SimpleAuthWebService/SimpleAuth.asmx" ----- Fail

How should i do?

Thank you!

Tags (1)
0 Karma
1 Solution

kristian_kolb
Ultra Champion

Could this work? Should remove the string 'url=' and all non-space characters directly following it.

SEDCMD-nourl = s/\surl=\S+/ /g

EDIT: small change to replace url with " " instead of \s.

Hope this helps,

K

View solution in original post

0 Karma

chengyu
Path Finder

Thank you kindly support!

0 Karma

kristian_kolb
Ultra Champion

Could this work? Should remove the string 'url=' and all non-space characters directly following it.

SEDCMD-nourl = s/\surl=\S+/ /g

EDIT: small change to replace url with " " instead of \s.

Hope this helps,

K

0 Karma

chengyu
Path Finder

Thank you kindly support!

0 Karma

rturk
Builder

I'm sorry chengyu, it's not very clear to me what you are asking or what you are trying to achieve.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...