Splunk Search

How to setup regex to not index a specific URL?

iabreu
New Member

Hello Splunkers,

I'm having a little difficulty getting a regex on Splunk to not index a specifc URL. I tried many types of regexes, but none of them work. Below is the URL:

hxxps://xxcomputer.drmtz.com.br

Could you help me?

thanks.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could do this in props.conf:

[your_sourcetype]
...
TRANSFORMS-null = filter_url

And in transforms.conf:

[filter_url]
REGEX = https://\d+computer.drmtz.com.br
DEST_KEY = queue
FORMAT = nullQueue

That'll send events containing that URL to /dev/null. I've assumed that the xx stands for a number. Note, this will catch and drop every event containing that string anywhere in its raw text.
Remember to restart your indexers after making this change.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...