Hi Ninja
I've done a field extraction for apache access log like Referer.
Referer= http(s)://FQDN/Abc/dasd/sadfasf/
Now I am trying to get only FQDN
from the referer but field extractions is not allowing me to do this since that FQDN
is already in a field I extracted.
I want to create a table with count of unique FQDN
Application Count
FQDN1 4
FQDN2 30
Thanks.
Check out these great apps:
URL Parser: https://splunkbase.splunk.com/app/1545/
URL Toolbox: https://splunkbase.splunk.com/app/2734/
URL Expander (what is that tinyurl?): https://splunkbase.splunk.com/app/3460/
If you are happy to extract it in SPL (same regex can be used elsewhere like field extractor) then try to see if this works for you:
your base query to give field Referer
| rex field=Referer "https?:\/\/(?<FQDN>[^\/]+)\/.*"
| stats count by FQDN