below example : matching employee with 100 and 800 are accessing comments url
localhost/employees/100/comments 
localhost/employees/800/comments
matching 600 and 900 id having 3 messages
localhost/employees/600/messages/3
localhost/employees/900/messages/3
httpRequest
localhost/employees/100/comments 
localhost/employees/200/comments/10
localhost/employees/300/logs/1
localhost/employees/400/logs/3
localhost/employees/800/comments
localhost/employees/700/logs/10
localhost/employees/600/messages/3
baseURL/employees/400/message/3
okie..
what is the best way to exclude them from search result
         /
    /%00
    /%00/
    /%0a%
// 
//abx
//hell/**
/0960P011.png
/0l76F0VE.pfg
/1/
 
					
				
		
This is a duplicate question.... https://answers.splunk.com/answers/520428/how-to-group-urls-based-patterns.html#answer-519779
