Splunk Search

need regex to extract domain from url of mimecast,ironport logs

vsneha
New Member

Hi 

i need assistance in extracting domain from url received in ironport logs,url received in mimecast logs

i need the regex where we get only domain excluding :portnumber ,http/https/www.

 

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

could you give sample log entries, so community could help you.

r. Ismo

0 Karma

thambisetty
SplunkTrust
SplunkTrust

find below link useful.

Regular Expressions in Splunk 

————————————
If this helps, give a like below.
0 Karma

to4kawa
Ultra Champion

| rex "(?:GET|HEAD|PUT|OPTIONS|POST)\s(\w+:\/\/)?(?<url>[^\/:?]+)"

Was it like this?

 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...