Answer by warren for How do I remove specific parameters from URL in splunk?

@RichG suggested rex in sed mode

You can also use a pair of eval replace calls:

| eval URL=replace(URL,"\&PN[^\&]+","")
| eval URL=replace(URL,"\&accessType[^\&]+","")

from User warren – Stack Overflow https://stackoverflow.com/questions/73641768/how-do-i-remove-specific-parameters-from-url-in-splunk/73649313#73649313
via IFTTT