# How to split a url value separated by '?' and get top url

**URL:** <https://discuss.elastic.co/t/how-to-split-a-url-value-separated-by-and-get-top-url/150984>\
**Category:** Elasticsearch\
**Created:** [October 4, 2018, 7:22am UTC](https://discuss.elastic.co/t/how-to-split-a-url-value-separated-by-and-get-top-url/150984 "2018-10-04T07:22:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jogendra\_Jangid](https://avatars.discourse-cdn.com/v4/letter/j/5fc32e/32.png) [@Jogendra\_Jangid](https://discuss.elastic.co/u/Jogendra_Jangid)\
**Post date:** [October 4, 2018, 7:22am UTC](https://discuss.elastic.co/t/how-to-split-a-url-value-separated-by-and-get-top-url/150984/1 "2018-10-04T07:22:56Z")

</div>

Hi,

We have Nginx URL logs like below and trying to get top URLs by API name. so how can I ignore values after '?' the question mark and get API's.

/services/user/user\_messages?bid=xxxxxx&apikey=xxxxxxxxxxxx&start=xxxxxxxxx&end=xxxxxxxxxx  
/services/user\_accounts?_=xxxxxxx  
/services/user\_accounts?_=1xxxxxx  
/services/user\_accounts?\_=2xxxxxx

Thanks

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 4, 2018, 7:27am UTC](https://discuss.elastic.co/t/how-to-split-a-url-value-separated-by-and-get-top-url/150984/2 "2018-10-04T07:27:50Z")

</div>

You could use a grok or dissect filter at index time to parse out the base URL and store this in a separate field. This is most likely the most performant and scalable way to solve the problem.

---

<div class="post-metadata">

**Author:** ![Jogendra\_Jangid](https://avatars.discourse-cdn.com/v4/letter/j/5fc32e/32.png) [@Jogendra\_Jangid](https://discuss.elastic.co/u/Jogendra_Jangid)\
**Post date:** [October 4, 2018, 8:03am UTC](https://discuss.elastic.co/t/how-to-split-a-url-value-separated-by-and-get-top-url/150984/3 "2018-10-04T08:03:59Z")

</div>

I like to use this for dashboard visualisation only. don't want to change the actual data. is there any way to query in current logs data.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 4, 2018, 8:06am UTC](https://discuss.elastic.co/t/how-to-split-a-url-value-separated-by-and-get-top-url/150984/4 "2018-10-04T08:06:51Z")

</div>

Depending on how you want to use it, it may be possible to do this through a scripted field, but that is likely to be slow and not scale very well as there would be a fair bit of processing for every document for every query. If this is a common analysis. I would recommend adding it as a separate field.

---

<div class="post-metadata">

**Author:** ![Jogendra\_Jangid](https://avatars.discourse-cdn.com/v4/letter/j/5fc32e/32.png) [@Jogendra\_Jangid](https://discuss.elastic.co/u/Jogendra_Jangid)\
**Post date:** [October 4, 2018, 8:37am UTC](https://discuss.elastic.co/t/how-to-split-a-url-value-separated-by-and-get-top-url/150984/5 "2018-10-04T08:37:53Z")

</div>

Thanks @Christian_Dahlqvist. it is helpful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2018, 8:37am UTC](https://discuss.elastic.co/t/how-to-split-a-url-value-separated-by-and-get-top-url/150984/6 "2018-11-01T08:37:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
