Splunk Search

Different web page mentioned in the body of indexed log and another mentioned in its cs_uri_stem

subhadipc
Explorer

I see a different web page mentioned in the body of indexed log and another mentioned in its cs_uri_stem. For example, if I search with
host="trlpws003" AND "OrchMain.aspx",
I get a list of matching records. Now, when I search with
host="trlpws003" AND cs_uri_stem ="*CustomReport.aspx"
I do not find those rows.

I need to find the response times of "*CustomReport.aspx", but since cs_uri_stem ="*CustomReport.aspx" is not working, I am not able to retrieve the same.

Please help.

Tags (1)
0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

So what does your output look like when you run:

host="trlpws003" AND cs_uri_stem ="CustomReport.aspx"

is the stem being extracted correctly? Can you search for:

CustomReport.aspx

What does that output look like?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...