<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: REX command issue for Multiple user agent in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535051#M4861</link>
    <description>&lt;P&gt;You might try combining all of the regex strings into a single regex using |.&amp;nbsp; You'll likely need the (?J) flag to avoid errors about duplicate fields.&lt;/P&gt;&lt;P&gt;A better way is to use an existing app.&amp;nbsp; See TA-user-agents (&lt;A href="https://splunkbase.splunk.com/app/1843/" target="_blank"&gt;https://splunkbase.splunk.com/app/1843/&lt;/A&gt;) or TA-browscap (&lt;A href="https://splunkbase.splunk.com/app/1021/" target="_blank"&gt;https://splunkbase.splunk.com/app/1021/&lt;/A&gt;).&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jan 2021 14:18:25 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-01-07T14:18:25Z</dc:date>
    <item>
      <title>REX command issue for Multiple user agent</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535003#M4859</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;As every one knew there are multiple user agent depends on user device.&amp;nbsp; However i am trying to achieve the below output from the user agent using table command.&lt;/P&gt;&lt;P&gt;sample output&lt;/P&gt;&lt;TABLE width="805"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="67"&gt;os_family&lt;/TD&gt;&lt;TD width="74"&gt;os_version&lt;/TD&gt;&lt;TD width="140"&gt;device_brand_model&lt;/TD&gt;&lt;TD width="108"&gt;brower_enginer&lt;/TD&gt;&lt;TD width="144"&gt;brow_engine_version&lt;/TD&gt;&lt;TD width="102"&gt;hardware_type&lt;/TD&gt;&lt;TD width="58"&gt;browser&lt;/TD&gt;&lt;TD width="112"&gt;browser_version&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;User agent &amp;amp; Rex&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Iphone&lt;/STRONG&gt; -&amp;nbsp;Mozilla/5.0 (iPhone; CPU iPhone OS 14_2_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Mobile/15E148 Safari/604.1&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;REX&lt;/STRONG&gt; -&amp;nbsp;\((?&amp;lt;hardware_type&amp;gt;\w+);\s+[^ ]+\s(?&amp;lt;os_family&amp;gt;\w+\s[^ ]+)\s+(?&amp;lt;os_version&amp;gt;\w+)\s[^ ]+\s[^ ]+\s\w+\s\w.\s(?&amp;lt;browser_engine&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s+\(.+\)\s+(?&amp;lt;browser_version&amp;gt;\w+\/[^ ]+)\s+\w+\/\w+\s(?&amp;lt;browser&amp;gt;\w+)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Xiaomi&lt;/STRONG&gt; -&amp;nbsp;Mozilla/5.0 (Linux; U; Android 9; en-gb; Redmi Note 6 Pro Build/PKQ1.180904.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/71.0.3578.141 Mobile Safari/537.36 XiaoMi/MiuiBrowser/12.7.4-gn&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;REX&lt;/STRONG&gt; -&amp;nbsp;\(\w+;\s\w;\s(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+);\s[^ ]+\s(?&amp;lt;device_brand_model&amp;gt;\w+\s[^ ]+\s[^ ]+)\s[^ ]+\s[^ ]+\s(?&amp;lt;browser_engine&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s\(.+\)\s\w+\/[^ ]+\s[^ ]+\s(?&amp;lt;hardware_type&amp;gt;\w+)\s[^ ]+\s(?&amp;lt;browser&amp;gt;\w+\/\w+)\/(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;One Plus&lt;/STRONG&gt; -&amp;nbsp;Mozilla/5.0 (Linux; Android 10; ONEPLUS A6013) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.101 Mobile Safari/537.36&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;REX&lt;/STRONG&gt; -&amp;nbsp;\(\w+;\s(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+[^ ]+)\s+(?&amp;lt;device_brand_model&amp;gt;\w+\s[^ ]+)\s(?&amp;lt;browser_engine&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s\(.+\)\s(?&amp;lt;browser&amp;gt;\w+)\/(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)\s(?&amp;lt;hardware_type&amp;gt;\w+)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Windows&lt;/STRONG&gt; -&amp;nbsp;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36 Edge/87.0.664.66&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;REX&lt;/STRONG&gt; -&amp;nbsp;\((?&amp;lt;os_family&amp;gt;\w+)\s+\w+\s+(?&amp;lt;os_version&amp;gt;[^;]+)[^\)]+\)\s(?&amp;lt;browser_egnine&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s\(.+\)\s[^ ]+\s[^ ]+\s(?&amp;lt;browser&amp;gt;\w+)\/(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Macintosh&lt;/STRONG&gt; -&amp;nbsp;Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.2 Safari/605.1.15"&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;REX&lt;/STRONG&gt; -&amp;nbsp;\((?&amp;lt;hardware_type&amp;gt;\w+);\s\w+\s+(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+\s[^ ]+\s[^ ]+)\s(?&amp;lt;browser_enginer&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s\(.+\)\s(?&amp;lt;browser_version&amp;gt;\w+\/[^ ]+)\s(?&amp;lt;browser&amp;gt;\w+)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Lenovo&lt;/STRONG&gt; -&amp;nbsp;Mozilla/5.0 (Linux; Android 6.0.1; Lenovo YT3-X90F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.101 Safari/537.36&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;REX&lt;/STRONG&gt; -&amp;nbsp;\(\w+;\s(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+[^ ]+)\s+(?&amp;lt;device_brand_model&amp;gt;\w+\s\w+[^ ]+)\s+(?&amp;lt;browser_engine&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s\(.+\)\s(?&amp;lt;browser&amp;gt;\w+)\/(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)&lt;/P&gt;&lt;P&gt;Like above i have created multiple REX command for ( Ipad/HP/Meizu/Vivo/Motorola/Lenovo/ZTE blade /One Plus / Xiaomi / Google Pixel / Android / LG / Asus/&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know can we run spl cmd&amp;nbsp; with multiple REX command in single search or how can get the output i am expected to obtain all user agent details.&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 03:22:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535003#M4859</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2021-01-07T03:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: REX command issue for Multiple user agent</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535051#M4861</link>
      <description>&lt;P&gt;You might try combining all of the regex strings into a single regex using |.&amp;nbsp; You'll likely need the (?J) flag to avoid errors about duplicate fields.&lt;/P&gt;&lt;P&gt;A better way is to use an existing app.&amp;nbsp; See TA-user-agents (&lt;A href="https://splunkbase.splunk.com/app/1843/" target="_blank"&gt;https://splunkbase.splunk.com/app/1843/&lt;/A&gt;) or TA-browscap (&lt;A href="https://splunkbase.splunk.com/app/1021/" target="_blank"&gt;https://splunkbase.splunk.com/app/1021/&lt;/A&gt;).&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 14:18:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535051#M4861</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-07T14:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: REX command issue for Multiple user agent</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535105#M4862</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems the browscap is not compatible with our version of Splunk. Could you please recommend list of various option ( Addon app ) to capture user agent details.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 20:41:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535105#M4862</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2021-01-07T20:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: REX command issue for Multiple user agent</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535188#M4864</link>
      <description>&lt;P&gt;Check splunkbase for other app that are compatible with your version of Splunk.&lt;/P&gt;&lt;P&gt;Consider updating the browscap app to be compatible with your version of Splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2021 13:43:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535188#M4864</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-08T13:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: REX command issue for Multiple user agent</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535284#M4866</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could d you please give me some sample how do i join multiple REX command.&lt;/P&gt;&lt;P&gt;Sorry i am new and learning Splunk.&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 03:13:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535284#M4866</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2021-01-11T03:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: REX command issue for Multiple user agent</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535343#M4867</link>
      <description>&lt;P&gt;My advice was to join multiple regex strings, not multiple rex commands.&amp;nbsp; You would have a single rex command that would search for many regular expressions.&amp;nbsp; It would look something like this.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... | rex "(\((?&amp;lt;hardware_type&amp;gt;\w+);\s+[^ ]+\s(?&amp;lt;os_family&amp;gt;\w+\s[^ ]+)\s+(?&amp;lt;os_version&amp;gt;\w+)\s[^ ]+\s[^ ]+\s\w+\s\w.\s(?&amp;lt;browser_engine&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s+\(.+\)\s+(?&amp;lt;browser_version&amp;gt;\w+\/[^ ]+)\s+\w+\/\w+\s(?&amp;lt;browser&amp;gt;\w+))|(\(\w+;\s\w;\s(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+);\s[^ ]+\s(?&amp;lt;device_brand_model&amp;gt;\w+\s[^ ]+\s[^ ]+)\s[^ ]+\s[^ ]+\s(?&amp;lt;browser_engine&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s\(.+\)\s\w+\/[^ ]+\s[^ ]+\s(?&amp;lt;hardware_type&amp;gt;\w+)\s[^ ]+\s(?&amp;lt;browser&amp;gt;\w+\/\w+)\/(?&amp;lt;browser_version&amp;gt;\w+[^ ]+))"
| ...&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 11 Jan 2021 13:41:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535343#M4867</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-11T13:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: REX command issue for Multiple user agent</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535420#M4868</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I tried the above rex command getting error msg.&lt;/P&gt;&lt;P&gt;Sorry about my poor knowledge in Splunk&lt;/P&gt;&lt;PRE&gt;| rex "(\((?&amp;lt;hardware_type&amp;gt;\w+);\s+[^ ]+\s(?&amp;lt;os_family&amp;gt;\w+\s[^ ]+)\s+(?&amp;lt;os_version&amp;gt;\w+)\s[^ ]+\s[^ ]+\s\w+\s\w.\s(?&amp;lt;browser_engine&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s+\(.+\)\s+(?&amp;lt;browser_version&amp;gt;\w+\/[^ ]+)\s+\w+\/\w+\s(?&amp;lt;browser&amp;gt;\w+))|(\(\w+;\s\w;\s(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+);\s[^ ]+\s(?&amp;lt;device_brand_model&amp;gt;\w+\s[^ ]+\s[^ ]+)\s[^ ]+\s[^ ]+\s(?&amp;lt;browser_engine&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s\(.+\)\s\w+\/[^ ]+\s[^ ]+\s(?&amp;lt;hardware_type&amp;gt;\w+)\s[^ ]+\s(?&amp;lt;browser&amp;gt;\w+\/\w+)\/(?&amp;lt;browser_version&amp;gt;\w+[^ ]+))&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1610421481941.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12502i1403E6E01F5CBAEB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1610421481941.png" alt="jaibalaraman_0-1610421481941.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 03:20:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535420#M4868</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2021-01-12T03:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: REX command issue for Multiple user agent</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535487#M4869</link>
      <description>&lt;P&gt;The example was just that - an example.&amp;nbsp; As I mentioned in my first reply, you'll have to account for multiple uses of the same field (named capture group).&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 14:40:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535487#M4869</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-12T14:40:28Z</dc:date>
    </item>
  </channel>
</rss>

