Splunk Search

sed replace help

mcbradford
Contributor

I am using the following:

eval link=http_referrer+uri_path | top link

and I get

http://www.foxnews.com//static/includes/partners/dma/520.html

I want to remove the double "//" and replace it with just one "/"

I cannot get my regex to work???

Tags (1)

Ayn
Legend
... | rex mode=sed field=link "s/\/\//\//"

mcbradford
Contributor

|eval http_referrer = substr(http_referrer, 1, len(http_referrer)-1)| eval link=http_referrer+uri_path |

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...