Splunk Search

Splunk parse url path value (not query parameter)

srinathv77
Engager

www-pcm-com/p/Logitech-Keyboards/product~dpno~8146199~pdp.gbhdbgh

How can i get the value 8146199 (which will always be followed by "~dpno~" ?

I want only 8146199.

Tags (2)
0 Karma

linu1988
Champion

Try this

sourcetype=xxx| rex field=_raw/field_name "~dpno~(?<Val>\\d+)" |table Val

field_name= address/ something which has been extracted by splunk

somesoni2
Revered Legend

Try this

..your base search ..| rex field=url "dpno~(?<YourFieldName>[^~]+)"

srinathv77
Engager

Thank you for quick response.

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk &#43; Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...