How to split a url value separated by '?' and get top url

(Jogendra Jangid) #1


We have Nginx URL logs like below and trying to get top URLs by API name. so how can I ignore values after '?' the question mark and get API's.



(Christian Dahlqvist) #2

You could use a grok or dissect filter at index time to parse out the base URL and store this in a separate field. This is most likely the most performant and scalable way to solve the problem.

(Jogendra Jangid) #3

I like to use this for dashboard visualisation only. don't want to change the actual data. is there any way to query in current logs data.

(Christian Dahlqvist) #4

Depending on how you want to use it, it may be possible to do this through a scripted field, but that is likely to be slow and not scale very well as there would be a fair bit of processing for every document for every query. If this is a common analysis. I would recommend adding it as a separate field.

(Jogendra Jangid) #5

Thanks @Christian_Dahlqvist. it is helpful.

(system) #6

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.