Splunk Search

How to group URLs in my sample data while ignoring "/{id}" AND OR "/logs" or "/messages/" segments?

jw44250
New Member

below example : matching employee with 100 and 800 are accessing comments url
localhost/employees/100/comments
localhost/employees/800/comments

matching 600 and 900 id having 3 messages
localhost/employees/600/messages/3
localhost/employees/900/messages/3

httpRequest
localhost/employees/100/comments
localhost/employees/200/comments/10
localhost/employees/300/logs/1
localhost/employees/400/logs/3
localhost/employees/800/comments
localhost/employees/700/logs/10
localhost/employees/600/messages/3
baseURL/employees/400/message/3

0 Karma

jw44250
New Member

okie..
what is the best way to exclude them from search result
/

/%00

/%00/

/%0a%
//
//abx
//hell/**

0 Karma

jw44250
New Member

/0960P011.png
/0l76F0VE.pfg
/1/

0 Karma

niketn
Legend

This is a duplicate question.... https://answers.splunk.com/answers/520428/how-to-group-urls-based-patterns.html#answer-519779

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...