Splunk Search

How should i do SEDCMD filter URL?

chengyu
Path Finder

I have use Heave Forward and modify props.conf

source:...

SEDCMD-nourl = s/\surl=("\w+"|"\w+\[./\]"|)\s/ /g    

RAW data:
i.g:

url="N/A" -----OK

or

url="/bases/av/kdb/i386/kdb-i386-1211g.xml.dif" ----Fail

or

url="/SimpleAuthWebService/SimpleAuth.asmx" ----- Fail

How should i do?

Thank you!

Tags (1)
0 Karma
1 Solution

kristian_kolb
Ultra Champion

Could this work? Should remove the string 'url=' and all non-space characters directly following it.

SEDCMD-nourl = s/\surl=\S+/ /g

EDIT: small change to replace url with " " instead of \s.

Hope this helps,

K

View solution in original post

0 Karma

chengyu
Path Finder

Thank you kindly support!

0 Karma

kristian_kolb
Ultra Champion

Could this work? Should remove the string 'url=' and all non-space characters directly following it.

SEDCMD-nourl = s/\surl=\S+/ /g

EDIT: small change to replace url with " " instead of \s.

Hope this helps,

K

0 Karma

chengyu
Path Finder

Thank you kindly support!

0 Karma

rturk
Builder

I'm sorry chengyu, it's not very clear to me what you are asking or what you are trying to achieve.

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...