Splunk Search

need regex to extract domain from url of mimecast,ironport logs

vsneha
New Member

Hi 

i need assistance in extracting domain from url received in ironport logs,url received in mimecast logs

i need the regex where we get only domain excluding :portnumber ,http/https/www.

 

 

Labels (1)
0 Karma

soutamo
SplunkTrust
SplunkTrust

Hi

could you give sample log entries, so community could help you.

r. Ismo

0 Karma

thambisetty
Super Champion

find below link useful.

Regular Expressions in Splunk 

————————————
If this helps, give a like below.
0 Karma

to4kawa
SplunkTrust
SplunkTrust

| rex "(?:GET|HEAD|PUT|OPTIONS|POST)\s(\w+:\/\/)?(?<url>[^\/:?]+)"

Was it like this?

 

0 Karma