<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OS and browser extraction from useragent in Security</title>
    <link>https://community.splunk.com/t5/Security/OS-and-browser-extraction-from-useragent/m-p/36824#M1222</link>
    <description>&lt;P&gt;Is this better than &lt;STRONG&gt;TA-browscap&lt;/STRONG&gt;?  I'm trying to eval all these Apps to figure out which one to use.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Sep 2019 22:16:53 GMT</pubDate>
    <dc:creator>justdan23</dc:creator>
    <dc:date>2019-09-30T22:16:53Z</dc:date>
    <item>
      <title>OS and browser extraction from useragent</title>
      <link>https://community.splunk.com/t5/Security/OS-and-browser-extraction-from-useragent/m-p/36820#M1218</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I need to extract OS and browser details from useragent.&lt;BR /&gt;
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)&lt;BR /&gt;
 I need to capture Web Browser Version and Operating System Version from each user per visit. Is there any easy way that I can get the info instead of writing python script?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2012 09:15:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/OS-and-browser-extraction-from-useragent/m-p/36820#M1218</guid>
      <dc:creator>abhiram</dc:creator>
      <dc:date>2012-11-16T09:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: OS and browser extraction from useragent</title>
      <link>https://community.splunk.com/t5/Security/OS-and-browser-extraction-from-useragent/m-p/36821#M1219</link>
      <description>&lt;P&gt;Well, define 'easy'... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
How familiar are you with regular expressions? Given your example useragent string above, what are your desired values for &lt;BR /&gt;
 - Browser Version&lt;BR /&gt;
 - OS version&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2012 20:08:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/OS-and-browser-extraction-from-useragent/m-p/36821#M1219</guid>
      <dc:creator>stefandagerman</dc:creator>
      <dc:date>2012-11-16T20:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: OS and browser extraction from useragent</title>
      <link>https://community.splunk.com/t5/Security/OS-and-browser-extraction-from-useragent/m-p/36822#M1220</link>
      <description>&lt;P&gt;There is an app that provides a dynamic lookup for user agent strings; it is called &lt;STRONG&gt;TA-uas_parser&lt;/STRONG&gt;. Download it from&lt;/P&gt;

&lt;P&gt;&lt;A href="http://apps.splunk.com/app/1007"&gt;http://apps.splunk.com/app/1007&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;It's free. The user agent string can be very complex. I don't recommend that you build this yourself.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2013 04:19:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/OS-and-browser-extraction-from-useragent/m-p/36822#M1220</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-09-17T04:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: OS and browser extraction from useragent</title>
      <link>https://community.splunk.com/t5/Security/OS-and-browser-extraction-from-useragent/m-p/36823#M1221</link>
      <description>&lt;P&gt;I'm having trouble with this as well. The problem for me is I don't exactly know how to handle the varying information within the parenthesis. For example: &lt;/P&gt;

&lt;P&gt;Mozilla/5.0 (Windows NT 6.1; WOW64; rv:39.0) Gecko/20100101 Firefox/39.0&lt;BR /&gt;
Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)&lt;/P&gt;

&lt;P&gt;Here, the Windows NT 6.1 is in different locations, so it is very difficult to make a field extraction for Platform Token and Version Token. Any words of advice? &lt;/P&gt;

&lt;P&gt;Additionally: I am unable to use an app or script, as I do not have access, and will need advice for the query itself. &lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2015 22:22:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/OS-and-browser-extraction-from-useragent/m-p/36823#M1221</guid>
      <dc:creator>julianj</dc:creator>
      <dc:date>2015-07-10T22:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: OS and browser extraction from useragent</title>
      <link>https://community.splunk.com/t5/Security/OS-and-browser-extraction-from-useragent/m-p/36824#M1222</link>
      <description>&lt;P&gt;Is this better than &lt;STRONG&gt;TA-browscap&lt;/STRONG&gt;?  I'm trying to eval all these Apps to figure out which one to use.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2019 22:16:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/OS-and-browser-extraction-from-useragent/m-p/36824#M1222</guid>
      <dc:creator>justdan23</dc:creator>
      <dc:date>2019-09-30T22:16:53Z</dc:date>
    </item>
  </channel>
</rss>

