I have URL field on my log which i need to group/bucket:
Unfortunately the it has some varying data on it, such as:
https://172.18.10.41/api/v1.0/customer/inquiry/401301018517537
http://182.18.10.41/corp/rest/v1/01/custom/applications/502569/summary
how to change it into:
https://172.18.10.41/api/v1.0/customer/inquiry/userID
http://182.18.10.41/corp/rest/v1/01/custom/applications/ID/summary
for easier aggregation?
on ELK 7.10 Basic