Splunk Search

Is there a way to regex first part of the URL?

ebs
Communicator

Hi, 

All my URLs have this general format https://value.company.com.au/etc/ Is there a way I can extract URLs and always stop at the .au but also have this included in the field? Some differ with a port at the end so its goes https://value.company.com.au:9001 but I don't want the port or anything after the /.

Do you have any recommendations on what the regex would look like?

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
(?<url>https?:\/\/[^:\/]+)

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
(?<url>https?:\/\/[^:\/]+)

Badab
New Member

Hello,

Thanks for that, but it not works on my Splunk research, I get the following message :

Error in 'SearchParser': Missing a search command before '^'. Error at position '86' of search query 'search index=* sourcetype="os_win_wks:java:trace" ...{snipped} {errorcontext = tps?:\/\\[^:\/]+)}'.

Do you know why ?

Thanks

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Because you are not using it to extract the field correctly. Rather than trying to extend someone else's question, please ask a fresh question where you can define your usecase more fully.

ebs
Communicator

Thanks so much!

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...