Splunk Search

Is there a way to regex first part of the URL?

ebs
Communicator

Hi, 

All my URLs have this general format https://value.company.com.au/etc/ Is there a way I can extract URLs and always stop at the .au but also have this included in the field? Some differ with a port at the end so its goes https://value.company.com.au:9001 but I don't want the port or anything after the /.

Do you have any recommendations on what the regex would look like?

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
(?<url>https?:\/\/[^:\/]+)

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
(?<url>https?:\/\/[^:\/]+)

Badab
New Member

Hello,

Thanks for that, but it not works on my Splunk research, I get the following message :

Error in 'SearchParser': Missing a search command before '^'. Error at position '86' of search query 'search index=* sourcetype="os_win_wks:java:trace" ...{snipped} {errorcontext = tps?:\/\\[^:\/]+)}'.

Do you know why ?

Thanks

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Because you are not using it to extract the field correctly. Rather than trying to extend someone else's question, please ask a fresh question where you can define your usecase more fully.

ebs
Communicator

Thanks so much!

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...