Splunk Notes

URI Path for web application

If you want to look at the information for a web application with a specific uri path and accommodate any number of parameters
sitetolookat.com sourcetype=<some source type you have> url="/uri/path/file.php*"

Get traffic for an ip

tag=proxy ipaddress

Get traffic for a hostname

tag=proxy host="target.host"