March 2018
Beginner to intermediate
576 pages
13h 29m
English
Splunk lookups also support wildcards, which we can use in this case.
One advantage is that we can define arbitrary fields for grouping, independent of the values of url.
For a lookup wildcard to work, first we need to set up our url field and the lookup:
s[AZ]+s(?P<url>.*?)s. See Chapter 5, Tables, Charts, and Fields, for detailed instructions on setting up a field extraction. Don't forget to set permissions on the extraction.
url,section /about/*,about /contact/*,contact /*/*,unknown_non_root /*,root *,nomatch
Read now
Unlock full access