Splunk Search

REX

shreyasamin64
Explorer

REX command to create a field domain from website

EX:  input : https://www.youtube.com/sd/td/gs-intro

        output: www.youtube.com

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

This should work

 

| rex field=yourfield "//(?<domain>[^/?]*)"

 

 

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

This should work

 

| rex field=yourfield "//(?<domain>[^/?]*)"

 

 

aasabatini
Motivator

Hi @shreyasamin64 

try this

rex "(https:\/\/)(?<domain>\w+.\w+.\w+)"
“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
Get Updates on the Splunk Community!

Avoid Certificate Expiry Issues in Splunk Enterprise with Certificate Assist

This blog post is part 2 of 4 of a series on Splunk Assist. Click the links below to see the other ...

Using Machine Learning for Hunting Security Threats

REGISTER NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more ...

Security Highlights | November 2022 Newsletter

 November 2022 2022 Gartner Magic Quadrant for SIEM: Splunk Named a Leader for the 9th Year in a RowSplunk is ...