Reporting

How to combine multiple uri_paths in a report to show data for the single corresponding application?

SaiKalyani
Engager

Hi All
Suppose i have different uri_paths for single application X
ex : /abc/xyz/, 123/abc/, xyz/wer/*
i want to show a report in which i can say for all of these uri_paths it should show me the data as Application name X

Tags (4)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could define a tag on that field and store all the valid values for application X under one tag value. Then you can search for tag::uri_path=application_X.
Alternatively, you could define a lookup that maps URIs to applications, add that lookup to your data, and then use that lookup field as your classification.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...