Splunk Search

How to extract a URL from a text string and assign it to a variable in Splunk?

Cuyose
Builder

I cannot find a working example of this anywhere. I can find examples a mile long on google, but am having trouble actually assigning them to a variable in Splunk.

0 Karma
1 Solution

Cuyose
Builder

I got what I needed using the following:

|rex field=_raw "(?(https?:\/\/([-\w\.]+)+(:\d+)?))"

View solution in original post

0 Karma

Cuyose
Builder

I got what I needed using the following:

|rex field=_raw "(?(https?:\/\/([-\w\.]+)+(:\d+)?))"
0 Karma

sundareshr
Legend

Try this, for 3 capturing groups. You can name each group, if desired.

... | rex "https?:\/\/([^\.]+)\.([^\.]+)\.([^\/]+)"
0 Karma

twinspop
Influencer

Need a sample log entry

0 Karma

Cuyose
Builder

http or https
then ://
then anything up to .
then anything up to .
then anything up to first /

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...