Splunk Search

How to group URLs in my sample data while ignoring "/{id}" AND OR "/logs" or "/messages/" segments?

jw44250
New Member

below example : matching employee with 100 and 800 are accessing comments url
localhost/employees/100/comments
localhost/employees/800/comments

matching 600 and 900 id having 3 messages
localhost/employees/600/messages/3
localhost/employees/900/messages/3

httpRequest
localhost/employees/100/comments
localhost/employees/200/comments/10
localhost/employees/300/logs/1
localhost/employees/400/logs/3
localhost/employees/800/comments
localhost/employees/700/logs/10
localhost/employees/600/messages/3
baseURL/employees/400/message/3

0 Karma

jw44250
New Member

okie..
what is the best way to exclude them from search result
/

/%00

/%00/

/%0a%
//
//abx
//hell/**

0 Karma

jw44250
New Member

/0960P011.png
/0l76F0VE.pfg
/1/

0 Karma

niketn
Legend

This is a duplicate question.... https://answers.splunk.com/answers/520428/how-to-group-urls-based-patterns.html#answer-519779

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...