Is there a simple way to remove everything after website.com
Currently I have several urls imported into splunk, some of which has full paths following .com
Any pointers would be great!
| rex field=url_field "http(|s):\/\/(?<url>[^\/]+)"
Please try below;
| rex field=url_field "^(?<cleaned_url>[^\/]+)"
| table url_field cleaned_url
I should have mentioned that there is https:// in front of the url's.
My results are