Splunk Search

Is there a way to regex first part of the URL?

ebs
Communicator

Hi, 

All my URLs have this general format https://value.company.com.au/etc/ Is there a way I can extract URLs and always stop at the .au but also have this included in the field? Some differ with a port at the end so its goes https://value.company.com.au:9001 but I don't want the port or anything after the /.

Do you have any recommendations on what the regex would look like?

Labels (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
(?<url>https?:\/\/[^:\/]+)

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
(?<url>https?:\/\/[^:\/]+)

Badab
New Member

Hello,

Thanks for that, but it not works on my Splunk research, I get the following message :

Error in 'SearchParser': Missing a search command before '^'. Error at position '86' of search query 'search index=* sourcetype="os_win_wks:java:trace" ...{snipped} {errorcontext = tps?:\/\\[^:\/]+)}'.

Do you know why ?

Thanks

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Because you are not using it to extract the field correctly. Rather than trying to extend someone else's question, please ask a fresh question where you can define your usecase more fully.

ebs
Communicator

Thanks so much!

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...