<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Browser Version from useragent in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-extract-using-Browser-Version-from-useragent/m-p/584900#M11566</link>
    <description>&lt;P&gt;There is no universal standard adopted by all browsers for the format of the user agent string, so any set of regex to extract this is likely to be incomplete at best.&lt;/P&gt;</description>
    <pubDate>Mon, 14 Feb 2022 06:16:41 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2022-02-14T06:16:41Z</dc:date>
    <item>
      <title>How to extract using Browser Version from useragent</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-extract-using-Browser-Version-from-useragent/m-p/584888#M11564</link>
      <description>&lt;P&gt;Hi, Is there a easy and straight forward way of extracting browser versions from access logs using Useragent string.&lt;/P&gt;
&lt;P&gt;I've a requirement where I have to list out top browsers and top versions of the browser. I was able to manage to extract the browser using the below eval expression&amp;nbsp; but getting the browser versions are tricky.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;| eval browser = case(match(useragent,"Firefox"),"FireFox", match(useragent,"Chrome") AND NOT match(useragent,"Edge"),"Chrome", match(useragent,"Safari") AND NOT match(useragent,"Chrome"),"Safari", match(useragent, "MSIE|Trident|Edge"), "IE", NOT match(useragent, "Chrome|Firefox|Safari|MSIE|Trident|Edge"), "OTHERS")&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has someone done that before and help me steer into right direction. I can't install any app so it has to be done via some regex. Please let me know if someone can help. Very much appreciated in advance&lt;/P&gt;
&lt;P&gt;Some examples of Useragent Strings -&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN class=""&gt;Mozilla/5.0&lt;/SPAN&gt; (&lt;SPAN class=""&gt;Linux&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Android&lt;/SPAN&gt; &lt;SPAN class=""&gt;9&lt;/SPAN&gt;; &lt;SPAN class=""&gt;ANE-LX1&lt;/SPAN&gt;) &lt;SPAN class=""&gt;AppleWebKit/537.36&lt;/SPAN&gt; (&lt;SPAN class=""&gt;KHTML&lt;/SPAN&gt;, &lt;SPAN class=""&gt;like&lt;/SPAN&gt; &lt;SPAN class=""&gt;Gecko&lt;/SPAN&gt;) &lt;SPAN class=""&gt;Chrome/98.0.4758.87&lt;/SPAN&gt; &lt;SPAN class=""&gt;Mobile&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Safari/537&lt;/SPAN&gt;.&lt;SPAN class=""&gt;36&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Mozilla/5.0&lt;/SPAN&gt; (&lt;SPAN class=""&gt;Macintosh&lt;/SPAN&gt;; &lt;SPAN class=""&gt;Intel&lt;/SPAN&gt; &lt;SPAN class=""&gt;Mac&lt;/SPAN&gt; &lt;SPAN class=""&gt;OS&lt;/SPAN&gt; &lt;SPAN class=""&gt;X&lt;/SPAN&gt; &lt;SPAN class=""&gt;10_15_7&lt;/SPAN&gt;) &lt;SPAN class=""&gt;AppleWebKit/605.1.15&lt;/SPAN&gt; (&lt;SPAN class=""&gt;KHTML&lt;/SPAN&gt;, &lt;SPAN class=""&gt;like&lt;/SPAN&gt; &lt;SPAN class=""&gt;Gecko&lt;/SPAN&gt;) &lt;SPAN class=""&gt;Version/15.3&lt;/SPAN&gt; &lt;SPAN class=""&gt;Safari/605.1.15&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Mozilla/5.0 (Linux; Android 9; ANE-LX1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.87 Mobile Safari/537.36&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Mozilla/5.0 (iPhone; CPU iPhone OS 15_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) GSA/198.0.425262635 Mobile/15E148 Safari/604.1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Best Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Shashank&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 15:54:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-extract-using-Browser-Version-from-useragent/m-p/584888#M11564</guid>
      <dc:creator>shashank_24</dc:creator>
      <dc:date>2022-02-14T15:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: Browser Version from useragent</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-extract-using-Browser-Version-from-useragent/m-p/584900#M11566</link>
      <description>&lt;P&gt;There is no universal standard adopted by all browsers for the format of the user agent string, so any set of regex to extract this is likely to be incomplete at best.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 06:16:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-extract-using-Browser-Version-from-useragent/m-p/584900#M11566</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-02-14T06:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Browser Version from useragent</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-extract-using-Browser-Version-from-useragent/m-p/584903#M11567</link>
      <description>&lt;P&gt;There is a requirement in HTTP 1.1 RFC describing the User-Agent format&lt;/P&gt;&lt;P&gt;&lt;A href="https://datatracker.ietf.org/doc/html/rfc7231#section-5.5.3" target="_blank" rel="noopener"&gt;https://datatracker.ietf.org/doc/html/rfc7231#section-5.5.3&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;PRE&gt;A user agent SHOULD send a User-Agent field in each request
   unless specifically configured not to do so.

     User-Agent = product *( RWS ( product / comment ) )

   The User-Agent field-value consists of one or more product
   identifiers, each followed by zero or more comments (&lt;A href="https://datatracker.ietf.org/doc/html/rfc7230#section-3.2" target="_blank" rel="noopener"&gt;Section&amp;nbsp;3.2 of
   [RFC7230]&lt;/A&gt;), which together identify the user agent software and its
   significant subproducts.  By convention, the product identifiers are
   listed in decreasing order of their significance for identifying the
   user agent software.&lt;/PRE&gt;&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Theoretically, a "product" and "version" here should be a "token", which means it should NOT include whitespace. And "comment" is any string contained within parentheses.&lt;/P&gt;&lt;P&gt;You have to remember though that it's "just" an RFC and User-Agent is a user-side supplied value so you can have anything in there but you might probably classify all those outliers as "other".&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 06:47:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-extract-using-Browser-Version-from-useragent/m-p/584903#M11567</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-14T06:47:46Z</dc:date>
    </item>
  </channel>
</rss>

