below example : matching employee with 100 and 800 are accessing comments url
localhost/employees/100/comments
localhost/employees/800/comments
matching 600 and 900 id having 3 messages
localhost/employees/600/messages/3
localhost/employees/900/messages/3
httpRequest
localhost/employees/100/comments
localhost/employees/200/comments/10
localhost/employees/300/logs/1
localhost/employees/400/logs/3
localhost/employees/800/comments
localhost/employees/700/logs/10
localhost/employees/600/messages/3
baseURL/employees/400/message/3
okie..
what is the best way to exclude them from search result
/
/%00
/%00/
/%0a%
//
//abx
//hell/**
/0960P011.png
/0l76F0VE.pfg
/1/
This is a duplicate question.... https://answers.splunk.com/answers/520428/how-to-group-urls-based-patterns.html#answer-519779