@RichG suggested rex in sed mode
You can also use a pair of eval replace calls:
| eval URL=replace(URL,"\&PN[^\&]+","")
| eval URL=replace(URL,"\&accessType[^\&]+","")
from User warren – Stack Overflow https://stackoverflow.com/questions/73641768/how-do-i-remove-specific-parameters-from-url-in-splunk/73649313#73649313
via IFTTT