Splunk Search

How to extract Top Level Domains from events?

waJesu
Path Finder

I need a query that extracts TLDs from events and compares the results with a lookup table with blocklisted TLDs

Labels (1)
Tags (2)
0 Karma

waJesu
Path Finder

I tried to use 

sourcetype=<sourcetypename> |rex field=_raw "(?<TLD>\.\w+?)(?:$|\/)" | table TLD

It returned TLDs but included values I think maybe part of IPs e.g. .33, .136, .74 etc. 

0 Karma
Get Updates on the Splunk Community!

Buttercup Games Tutorial Extension - part 9

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games Tutorial Extension - part 8

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Introducing the Splunk Developer Program!

Hey Splunk community! We are excited to announce that Splunk is launching the Splunk Developer Program in ...