<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User agent - Difficult in extracting Field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528771#M149286</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried creating the below REX "&amp;nbsp;&lt;BR /&gt;\(.*(?&amp;lt;Device&amp;gt;SAMSUNG\s+SM-\d+|Windows NT\s\d+|iPhone;|SAMSUNG\sSM-\d+)"&lt;/P&gt;&lt;P&gt;Its not working 100%&amp;nbsp; the output i can see only window &amp;amp; Iphone not samsung, hp etc&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1604976955317.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11828i125E79152F5A4759/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1604976955317.png" alt="jaibalaraman_0-1604976955317.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Nov 2020 02:56:05 GMT</pubDate>
    <dc:creator>jaibalaraman</dc:creator>
    <dc:date>2020-11-10T02:56:05Z</dc:date>
    <item>
      <title>User agent - Difficult in extracting Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528468#M149232</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to extract field from the user agent details like ( Operating system, Software, Software version, Software type, Os version, Hardware type)&amp;nbsp;&lt;/P&gt;&lt;P&gt;However i am finding some difficulty extracting the field . For example Operation system in Android, IOS &amp;amp; desktop are in the different field which highlighted below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Android user&lt;/STRONG&gt; -&amp;nbsp;&lt;SPAN class="t"&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Linux&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;FONT color="#33CCCC"&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;Android&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;SAMSUNG&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SM-T590&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class="t"&gt;AppleWebKit/537.36&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class="t"&gt;SamsungBrowser / 12.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Chrome/79.0.3945.136&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Safari/537.36&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;Iphone user&lt;/STRONG&gt; -&amp;nbsp;&lt;SPAN class="t"&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;iPhone&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class="t"&gt;CPU&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;iPhone&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;FONT color="#33CCCC"&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;OS&lt;/SPAN&gt; &lt;SPAN class="t"&gt;14_1&lt;/SPAN&gt; &lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Mac&lt;/SPAN&gt; &lt;SPAN class="t"&gt;OS&lt;/SPAN&gt; &lt;SPAN class="t"&gt;X&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class="t"&gt;AppleWebKit/605.1.15&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Version/14.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Mobile/15E148&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Safari/604.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Desktop user&lt;/STRONG&gt; -&amp;nbsp;&lt;SPAN class="t"&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;FONT color="#33CCCC"&gt;&lt;STRONG&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Windows&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;NT&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10.0&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Win64&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class="t"&gt;x64&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class="t"&gt;AppleWebKit/537.36&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Chrome/86.0.4240.111&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Safari/537.36&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;can someone help me how do extract field from the above user agent&amp;nbsp;&lt;/P&gt;&lt;P&gt;Software, Software version, Hardware type, Operation System,&amp;nbsp; Operating system name , Operation system version.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 03:25:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528468#M149232</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-11-09T03:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: User agent - Difficult in extracting Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528538#M149252</link>
      <description>&lt;P&gt;There is no single agreed standard for user agent strings. Probably the best you could do is to use rex to pick out matching strings and if none is found tag it as unrecognised e.g.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "\(.*(?&amp;lt;OS&amp;gt;Android\s\d+|OS \d+_\d+|Windows NT\s\d+\.\d+)\;?.*\)"
| fillnull value="unrecognised" OS&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 09 Nov 2020 14:49:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528538#M149252</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-11-09T14:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: User agent - Difficult in extracting Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528768#M149284</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the rex code, yes its working however i am able to extract only OS( Operation System) also i am looking for the below&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to extract&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF00FF"&gt;Text color&lt;/FONT&gt; - &lt;FONT color="#FF00FF"&gt;Represent user device&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF00FF"&gt;&lt;FONT color="#FF0000"&gt;Text color&lt;/FONT&gt;&amp;nbsp; - &lt;FONT color="#FF0000"&gt;Represent Software (Browser )&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Android user&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&amp;nbsp;&lt;SPAN class="t"&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Linux&lt;/SPAN&gt;&lt;SPAN&gt;;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#33CCCC"&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;Android&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;10&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF00FF"&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;SAMSUNG&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;SMT590&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;AppleWebKit/537.36&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t"&gt;SamsungBrowser / 12.1&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Chrome/79.0.3945.136&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Safari/537.36&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;Iphone &lt;/FONT&gt;user&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&amp;nbsp;&lt;SPAN class="t"&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;FONT color="#FF00FF"&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;iPhone&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;CPU&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;iPhone&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#33CCCC"&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;OS&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;14_1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Mac&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;OS&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;X&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;AppleWebKit/605.1.15&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN class="t"&gt;Version/14.0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN class="t"&gt;&lt;FONT color="#FF00FF"&gt;Mobile&lt;/FONT&gt;/15E148&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Safari/604.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Desktop user&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&amp;nbsp;&lt;SPAN class="t"&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;FONT color="#33CCCC"&gt;&lt;STRONG&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;Windows&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;NT&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;10.0&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF00FF"&gt;&lt;SPAN class="t"&gt;Win64&lt;/SPAN&gt;&lt;SPAN&gt;;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;x64&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;AppleWebKit/537.36&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;FONT color="#FF0000"&gt;Chrome/86.0&lt;/FONT&gt;.4240.111&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Safari/537.36&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;HP device&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Mozilla/5.0&lt;SPAN&gt; (&lt;/SPAN&gt;Linux&lt;SPAN&gt;; &lt;/SPAN&gt;Android 5.1.1&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;FONT color="#FF00FF"&gt;&lt;SPAN class="t a"&gt;HP&lt;/SPAN&gt; Pro Slate 12&lt;/FONT&gt; Build/LMY47V&lt;SPAN&gt;; &lt;/SPAN&gt;wv&lt;SPAN&gt;) &lt;/SPAN&gt;AppleWebKit/537.36&lt;SPAN&gt; (&lt;/SPAN&gt;KHTML&lt;SPAN&gt;, &lt;/SPAN&gt;like Gecko&lt;SPAN&gt;) &lt;/SPAN&gt;Version/4.0 &lt;FONT color="#FF0000"&gt;Chrome/68&lt;/FONT&gt;.0.3440.91 Safari/537.36&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Nokia&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Mozilla/5.0&lt;SPAN&gt; (&lt;/SPAN&gt;Linux&lt;SPAN&gt;; &lt;/SPAN&gt;Android 10&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;FONT color="#FF00FF"&gt;&lt;SPAN class="t a"&gt;Nokia&lt;/SPAN&gt; 7.1&lt;/FONT&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;AppleWebKit/537.36&lt;SPAN&gt; (&lt;/SPAN&gt;KHTML&lt;SPAN&gt;, &lt;/SPAN&gt;like Gecko&lt;SPAN&gt;) &lt;/SPAN&gt;Chrome/77.0.3865.116 Mobile Safari/537.36 &lt;FONT color="#FF0000"&gt;EdgA/45&lt;/FONT&gt;.09.4.5083&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Also i tried creating REX but unsuccessful (&amp;nbsp;\(.*(?&amp;lt;Software&amp;gt;SamsungBrowser\12.1\s*\d+) i dont know what is the mistake. Could you please help me on this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 01:50:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528768#M149284</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-11-10T01:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: User agent - Difficult in extracting Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528771#M149286</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried creating the below REX "&amp;nbsp;&lt;BR /&gt;\(.*(?&amp;lt;Device&amp;gt;SAMSUNG\s+SM-\d+|Windows NT\s\d+|iPhone;|SAMSUNG\sSM-\d+)"&lt;/P&gt;&lt;P&gt;Its not working 100%&amp;nbsp; the output i can see only window &amp;amp; Iphone not samsung, hp etc&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1604976955317.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/11828i125E79152F5A4759/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1604976955317.png" alt="jaibalaraman_0-1604976955317.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 02:56:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528771#M149286</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-11-10T02:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: User agent - Difficult in extracting Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528772#M149287</link>
      <description>&lt;P&gt;I am expecting the outcome "&amp;nbsp;&lt;/P&gt;&lt;TABLE width="299"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64"&gt;OS&lt;/TD&gt;&lt;TD width="64"&gt;Device&lt;/TD&gt;&lt;TD width="107"&gt;Browser details&amp;nbsp;&lt;/TD&gt;&lt;TD width="64"&gt;Browser Version&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 10 Nov 2020 02:57:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528772#M149287</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-11-10T02:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: User agent - Difficult in extracting Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528789#M149298</link>
      <description>&lt;P&gt;You may need to escape the hyphens and the slashes. You should try your rex at regex101.com - you can copy all the user agent lines in and see how well your rex works against them all. You may want to try breaking up the string into parts and using other rex on just parts e.g.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?&amp;lt;firstpart&amp;gt;[^\(]+)\((?&amp;lt;secondpart&amp;gt;[^\)]+)\)(?&amp;lt;thirdpart&amp;gt;[^\(]+)\((?&amp;lt;fourthpart&amp;gt;[^\)]+)\)(?&amp;lt;fifthpart&amp;gt;.*)"
| rex field=secondpart "(?&amp;lt;OS&amp;gt;Android|Windows|OS)"
| rex field=fifthpath "(?&amp;lt;browser&amp;gt;Safari|Chrome)"&lt;/LI-CODE&gt;&lt;P&gt;etc, Note that not all user agent strings follow this pattern so you still may get some that fall through, but you can find those and extend your rex to cover them all eventually (until a manufacturer brings out a new phone or OS that you hadn't accounted for!). This is an ongoing activity and you might want to question the value you are getting from knowing this information!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 07:41:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-Difficult-in-extracting-Field/m-p/528789#M149298</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-11-10T07:41:29Z</dc:date>
    </item>
  </channel>
</rss>

