Splunk Search

How to feed regex results of a query into another query?

crucifier_0
Explorer

My current Splunk regex query

10.66.189.62 -- -- -[17/May/2022:05:59:16--0400]--502- "POST /astra/sliceHTTP/1.1" req_len=1776-req_cont_len=117-req_cont_enc="-"-res_body_len=341 res_len=733 "https://ninepoint.blackrock.com/astra/". "Mozilla/5.0- (Macintosh; Intel-Mac-OS-X-10_15_7) -AppleWebKit/537.36-(KHTML,-Like-Gecko)
Chrome/10.0.4896.127 Safari/537.36" x_fw_for="-".req_time=278.326-ups_res_time=278.326 ups_con_time=0.011-ups_status=502-pipe=. -VNDRegID=undefined-

gives me;

POST /astra/sliceHTTP/1.1

 

I want to apply another query on the result of above query to get  POST/astra/sliceHTTP/1.1     ,i.e

/astra

Is there a way or a better regex pattern which can provide me the following?

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| rex field=_raw "\"\w*\s(?<url>\/[^\/]*)"

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

What is your current regex?

Are you wanting to do this at indexing or search time?

Will the string always start with POST?

0 Karma

crucifier_0
Explorer

My current regex is 

rex field=_raw \"\w*\s(?<url>.*?)\s.*\"

 

And it could start with POST or GET 

 

Thank you 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex field=_raw "\"\w*\s(?<url>\/[^\/]*)"

crucifier_0
Explorer

Thank you ITWhisperer, I was looking for the exact regex. 

0 Karma
Get Updates on the Splunk Community!

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...

4 Ways the Splunk Community Helps You Prepare for .conf25

.conf25 is right around the corner, and whether you’re a first-time attendee or a seasoned Splunker, the ...