I've done a field extraction for apache access log like Referer.
Now I am trying to get only FQDN from the referer but field extractions is not allowing me to do this since that FQDN is already in a field I extracted.
I want to create a table with count of unique FQDN
Check out these great apps:
URL Parser: https://splunkbase.splunk.com/app/1545/
URL Toolbox: https://splunkbase.splunk.com/app/2734/
URL Expander (what is that tinyurl?): https://splunkbase.splunk.com/app/3460/
If you are happy to extract it in SPL (same regex can be used elsewhere like field extractor) then try to see if this works for you:
your base query to give field Referer
| rex field=Referer "https?:\/\/(?<FQDN>[^\/]+)\/.*"
| stats count by FQDN
See extraction here