When a request comes on domain 1 (say abc.com) we do a 301 redirect to domain 2 (def.com). These will be two separate requests on my server access log. The original one (abc.com) ending up in 301 and the redirected one (def.com) ending up in 200 and both these requests are not synchronous or sequential.
How do I write a query to find the requests on the domain 1 (abc.com) which has redirected to domain 2 (def.com). I basically want to write something below:
domain="abc.com" http_status="301" response_location="def.com"
I don't think there is any response location identifier in splunk or is there one? Any help would be appreciated.
Thanks.
... View more