Splunk Search

How to extract a URL from a text string and assign it to a variable in Splunk?

Cuyose
Builder

I cannot find a working example of this anywhere. I can find examples a mile long on google, but am having trouble actually assigning them to a variable in Splunk.

0 Karma
1 Solution

Cuyose
Builder

I got what I needed using the following:

|rex field=_raw "(?(https?:\/\/([-\w\.]+)+(:\d+)?))"

View solution in original post

0 Karma

Cuyose
Builder

I got what I needed using the following:

|rex field=_raw "(?(https?:\/\/([-\w\.]+)+(:\d+)?))"
0 Karma

sundareshr
Legend

Try this, for 3 capturing groups. You can name each group, if desired.

... | rex "https?:\/\/([^\.]+)\.([^\.]+)\.([^\/]+)"
0 Karma

twinspop
Influencer

Need a sample log entry

0 Karma

Cuyose
Builder

http or https
then ://
then anything up to .
then anything up to .
then anything up to first /

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...