So, I want to create a table where it shows the time, source IP, and URL.
sourcetype=* src_ip=* url=* | table _time, src_ip, url
The search runs fine however the URL comes back with a long string.
Example= https://www.google.com/xxx_xxx?atyp=csi&ei=tWelWaipKMOJmQGb_Lr4Cg&s=newtab&action=update&ima=1&ime=0&mem=ujhs.10%2Ctjhs.10%2Cjhsl.2190&rt=aft.7%2Cxhr.191%2Cwsrt.326%2Ccst.0%2Cdnst.0%2Crqst.11%2Crspt.1%2Crqstt.146%2Crnt.130%2Ccstt.130%2Cdit.219&zx=1504023844621
Is there a way to trim the string from the URL to only show up to google.com/xxx_xxx?
... View more