<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need some help on rex command - User agent in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530939#M149983</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226870"&gt;@jaibalaraman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to identify distinct useragent formats to develop regex which will match 100% events.&lt;/P&gt;&lt;P&gt;For example if you look at below two events:&lt;/P&gt;&lt;P&gt;Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko&lt;BR /&gt;Mozilla/5.0 (Linux; Android 8.1.0; CPH1851) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Mobile Safari/537.36&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thambisetty_0-1606370786684.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12066i48398BB09FF66B6E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="thambisetty_0-1606370786684.png" alt="thambisetty_0-1606370786684.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you don't have same fields you have mentioned in your regex for the second event above.&lt;/P&gt;&lt;P&gt;If one regex is not going to match 100% events then you might need to create os1,os2 and then you need to coalesce all fields into&amp;nbsp; one field "os". you need to do same thing for other fields as well.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Nov 2020 06:06:35 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2020-11-26T06:06:35Z</dc:date>
    <item>
      <title>Need some help on rex command - User agent</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530735#M149929</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created the below rex command based on user agent using regular expression " regex101.com". The below rex command works fine in regex , please find below . However when i execute the same command in Splunk search i am getting an error message as&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;output&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Match 1&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;Full match&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;12-62&lt;/TD&gt;&lt;TD&gt;(Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;Group `os`&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;13-23&lt;/TD&gt;&lt;TD&gt;Windows NT&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;Group `os_version`&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;24-41&lt;/TD&gt;&lt;TD&gt;10.0; Win64; x64;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;Group `layout_engine`&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;42-49&lt;/TD&gt;&lt;TD&gt;Trident&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;Group `engine_version`&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;50-53&lt;/TD&gt;&lt;TD&gt;7.0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;Group `browser`&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;55-57&lt;/TD&gt;&lt;TD&gt;rv&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;Group `browser_version`&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;58-62&lt;/TD&gt;&lt;TD&gt;11.0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Err msg&lt;/STRONG&gt; -&lt;FONT face="arial black,avant garde"&gt;&lt;STRONG&gt;&amp;nbsp;rror in 'rex' command: regex="\((?&amp;lt;os&amp;gt;\w+\s+\w+)\s(?&amp;lt;os_version&amp;gt;[^;]+.[^\)][^;]+.[^\)][^;]+.)\s(?&amp;lt;layout_engine&amp;gt;\w+).(?&amp;lt;engine_version&amp;gt;\w+.\d+).\s(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+.\d+)" has exceeded configured match_limit, consider raising the value in limits.conf&lt;/STRONG&gt;&lt;/FONT&gt;.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;User agent&lt;/STRONG&gt; -&amp;nbsp;Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Rex command&lt;/STRONG&gt; -&amp;nbsp;| rex "\((?&amp;lt;os&amp;gt;\w+\s+\w+)\s(?&amp;lt;os_version&amp;gt;[^;]+.[^\)][^;]+.[^\)][^;]+.)\s(?&amp;lt;layout_engine&amp;gt;\w+).(?&amp;lt;engine_version&amp;gt;\w+.\d+).\s(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+.\d+)"&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 01:39:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530735#M149929</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-11-25T01:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help on rex command - User agent</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530747#M149934</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226870"&gt;@jaibalaraman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you would want to perform rex on field "useragent" then the syntax would be as below:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=useragent "(?&amp;lt;os&amp;gt;\w+\s+\w+)\s(?&amp;lt;os_version&amp;gt;[^;]+.[^\)][^;]+.[^\)][^;]+.)\s(?&amp;lt;layout_engine&amp;gt;\w+).(?&amp;lt;engine_version&amp;gt;\w+.\d+).\s(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+.\d+)"&lt;/LI-CODE&gt;&lt;P&gt;if you don't specify field in rex command the regex will be performed on _raw event.&lt;/P&gt;&lt;P&gt;working example is as below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval useragent="Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko" 
| rex field=useragent "(?&amp;lt;os&amp;gt;\w+\s+\w+)\s(?&amp;lt;os_version&amp;gt;[^;]+.[^\)][^;]+.[^\)][^;]+.)\s(?&amp;lt;layout_engine&amp;gt;\w+).(?&amp;lt;engine_version&amp;gt;\w+.\d+).\s(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+.\d+)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 05:24:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530747#M149934</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-11-25T05:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help on rex command - User agent</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530906#M149967</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129407"&gt;@thambisetty&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank for the information. Yes, the above rex command works fine only for the user agent.&lt;/P&gt;&lt;PRE&gt;"Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Geck&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eventually there are many user agent in can found in the log file list below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For example&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE width="1045"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="1045"&gt;Mozilla/5.0 (Linux; Android 8.1.0; CPH1851) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Mobile Safari/537.36&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (Linux; Android 5.1.1; HP Pro Slate 12 Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Safari/537.36&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (Linux; Android 8.0.0; SAMSUNG SM-G935F) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/12.1 Chrome/79.0.3945.136 Mobile Safari/537.36&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (iPhone; CPU iPhone OS 14_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/86.0.4240.93 Mobile/15E148 Safari/604.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (Linux; Android 10; SAMSUNG SM-G975F) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/12.1 Chrome/79.0.3945.136 Mobile Safari/537.36&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (iPhone; CPU iPhone OS 13_5_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1.1 Mobile/15E148 Safari/604.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (compatible; WormlyBot; +&lt;A href="http://wormly.com" target="_blank" rel="noopener"&gt;http://wormly.com&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (compatible; SemrushBot/7~bl; +&lt;A href="http://www.semrush.com/bot.html" target="_blank" rel="noopener"&gt;http://www.semrush.com/bot.html&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;swcd (unknown version) CFNetwork/1128.0.1 Darwin/19.6.0"&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;GoogleStackdriverMonitoring-UptimeChecks(&lt;A href="https://cloud.google.com/monitoring" target="_blank" rel="noopener"&gt;https://cloud.google.com/monitoring&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE width="1062"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="512"&gt;User agent&amp;nbsp;&lt;/TD&gt;&lt;TD width="550"&gt;Rex search&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="512"&gt;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36&lt;/TD&gt;&lt;TD width="550"&gt;| rex "\((?&amp;lt;os&amp;gt;\w+\s+\w+)\s(?&amp;lt;os_version&amp;gt;[^;]+)[^\)]+\).(?&amp;lt;layout_engine&amp;gt;\w+).(?&amp;lt;engine_version&amp;gt;\w+.\d+)\s[^\)]+\)\s+(?&amp;lt;browser&amp;gt;[^\/]+)\/(?&amp;lt;browser_version&amp;gt;[^ ]+)"&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="512"&gt;Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko&lt;/TD&gt;&lt;TD width="550"&gt;| rex field=useragent "(?&amp;lt;os&amp;gt;\w+\s+\w+)\s(?&amp;lt;os_version&amp;gt;[^;]+.[^\)][^;]+.[^\)][^;]+.)\s(?&amp;lt;layout_engine&amp;gt;\w+).(?&amp;lt;engine_version&amp;gt;\w+.\d+).\s(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+.\d+)"&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="512"&gt;Mozilla/5.0&amp;nbsp;(iPhone;&amp;nbsp;CPU&amp;nbsp;iPhone&amp;nbsp;OS&amp;nbsp;14_1&amp;nbsp;like&amp;nbsp;Mac&amp;nbsp;OS&amp;nbsp;X)&amp;nbsp;AppleWebKit/605.1.15&amp;nbsp;(KHTML,&amp;nbsp;like&amp;nbsp;Gecko)&amp;nbsp;Version/14.0&amp;nbsp;Mobile/15E148&amp;nbsp;Safari/604.1&lt;/TD&gt;&lt;TD width="550"&gt;| rex "\((?&amp;lt;mobile_device&amp;gt;\w+);\s+\w+\s+\w+\s+(?&amp;lt;os&amp;gt;\w+)\s+(?&amp;lt;os_version&amp;gt;\w+).*Version\/(?&amp;lt;software_version&amp;gt;[^ ]+)\s+\w+\/\w+\s+(?&amp;lt;software_name&amp;gt;\w+)\/\d+\.\d+$"&lt;BR /&gt;| replace "OS" with "iOS" in os&lt;BR /&gt;| replace "*_*" with "*.*" in os_version&lt;BR /&gt;| eval os_system=os." ".os_version&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="512"&gt;Mozilla/5.0&amp;nbsp;(Windows&amp;nbsp;NT&amp;nbsp;10.0;&amp;nbsp;Win64;&amp;nbsp;x64)&amp;nbsp;AppleWebKit/537.36&amp;nbsp;(KHTML,&amp;nbsp;like&amp;nbsp;Gecko)&amp;nbsp;Chrome/86.0.4240.111&amp;nbsp;Safari/537.36&lt;/TD&gt;&lt;TD width="550"&gt;&amp;nbsp;| rex "\((?&amp;lt;os&amp;gt;\w+)\s+\w+\s+(?&amp;lt;os_version&amp;gt;[^;]+)[^\)]+\)[^\)]+\)\s+(?&amp;lt;software_name&amp;gt;[^\/]+)\/(?&amp;lt;software_version&amp;gt;[^ ]+)"&lt;BR /&gt;| eval os_system=os." ".os_version&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="512"&gt;Mozilla/5.0&amp;nbsp;(Linux;&amp;nbsp;Android&amp;nbsp;10;&amp;nbsp;SAMSUNG&amp;nbsp;SMT590)&amp;nbsp;AppleWebKit/537.36&amp;nbsp;(KHTML,&amp;nbsp;like&amp;nbsp;Gecko)&amp;nbsp;SamsungBrowser / 12.1&amp;nbsp;Chrome/79.0.3945.136&amp;nbsp;Safari/537.36&lt;/TD&gt;&lt;TD width="550"&gt;| rex "\(\w+;\s+(?&amp;lt;os&amp;gt;\w+)\s+(?&amp;lt;os_version&amp;gt;\w+);.*SamsungBrowser\s+\/\s+\d+\.\d+\s+(?&amp;lt;software_name&amp;gt;[^\/]+)\/(?&amp;lt;software_version&amp;gt;[^ ]+)"&lt;BR /&gt;| eval os_system=os." ".os_version&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="512"&gt;Mozilla/5.0 (compatible; WormlyBot; +&lt;A href="http://wormly.com" target="_blank" rel="noopener"&gt;http://wormly.com&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="512"&gt;Mozilla/5.0 (compatible; SemrushBot/7~bl; +&lt;A href="http://www.semrush.com/bot.html" target="_blank" rel="noopener"&gt;http://www.semrush.com/bot.html&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="512"&gt;swcd (unknown version) Network/1128.0.1 Darwin/19.6.0"&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="512"&gt;GoogleStackdriverMonitoring-UptimeChecks(&lt;A href="https://cloud.google.com/monitoring" target="_blank" rel="noopener"&gt;https://cloud.google.com/monitoring&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="512"&gt;Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do i write single rex command which is common to all the user agent which gives me an output what i expect below&lt;/P&gt;&lt;TABLE width="866"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="56px" height="25px"&gt;os&lt;/TD&gt;&lt;TD width="90px" height="25px"&gt;os_version&lt;/TD&gt;&lt;TD width="113px" height="25px"&gt;layout_engine&lt;/TD&gt;&lt;TD width="117px" height="25px"&gt;layout_version&lt;/TD&gt;&lt;TD width="143px" height="25px"&gt;Hardware type&lt;/TD&gt;&lt;TD width="143px" height="25px"&gt;Hardware&amp;nbsp;&lt;/TD&gt;&lt;TD width="71px" height="25px"&gt;browser&lt;/TD&gt;&lt;TD width="132px" height="25px"&gt;browser_version&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="56px" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="90px" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="113px" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="117px" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="143px" height="47px"&gt;Samsung/ Iphone/ Desktop&lt;/TD&gt;&lt;TD width="143px" height="47px"&gt;Device model details&amp;nbsp;&lt;/TD&gt;&lt;TD width="71px" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="132px" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 22:18:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530906#M149967</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-11-25T22:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help on rex command - User agent</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530920#M149972</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226870"&gt;@jaibalaraman&lt;/a&gt;&amp;nbsp;.. check this query...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval useragent="Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko" 
| rex field=useragent "(?&amp;lt;os&amp;gt;\w+\s+\w+)\s(?&amp;lt;os_version&amp;gt;\d+\.\d+)\;\s(?&amp;lt;Hardware_type&amp;gt;\w+\d+)\;\s(?&amp;lt;Hardware&amp;gt;\w+\d+)\;\s(?&amp;lt;layout_engine&amp;gt;\w+).(?&amp;lt;engine_version&amp;gt;\w+.\d+).\s(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+.\d+)" 
|table os os_version layout_engine Hardware_type Hardware browser browser_version&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rex-browser.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12065i10DA39426DFC5636/image-size/large?v=v2&amp;amp;px=999" role="button" title="rex-browser.png" alt="rex-browser.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 00:12:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530920#M149972</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-11-26T00:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help on rex command - User agent</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530926#M149975</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the spl query works only for the particular user agent. which is "Trident".&lt;/P&gt;&lt;P&gt;As you aware there any many user agent&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;format is not always consistent, how do i write one spl query for all user agent or how do i run multiple rex spl command to execute unique result.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 01:06:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530926#M149975</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-11-26T01:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help on rex command - User agent</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530927#M149976</link>
      <description>&lt;P&gt;for other user-agents, other than&amp;nbsp;&lt;SPAN&gt;Trident, pls provide the sample logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;PS - karma points will be your 2 cents for my time, thanks.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 01:25:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530927#M149976</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-11-26T01:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help on rex command - User agent</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530929#M149978</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE width="1045"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="1045"&gt;Mozilla/5.0 (Linux; Android 8.1.0; CPH1851) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Mobile Safari/537.36&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Safari/605.1.15&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (Linux; Android 5.1.1; HP Pro Slate 12 Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Safari/537.36&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (Linux; Android 8.0.0; SAMSUNG SM-G935F) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/12.1 Chrome/79.0.3945.136 Mobile Safari/537.36&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (iPhone; CPU iPhone OS 14_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/86.0.4240.93 Mobile/15E148 Safari/604.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (Linux; Android 10; SAMSUNG SM-G975F) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/12.1 Chrome/79.0.3945.136 Mobile Safari/537.36&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (iPhone; CPU iPhone OS 13_5_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1.1 Mobile/15E148 Safari/604.1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (compatible; WormlyBot; +&lt;A href="http://wormly.com/" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;http://wormly.com&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (compatible; SemrushBot/7~bl; +&lt;A href="http://www.semrush.com/bot.html" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;http://www.semrush.com/bot.html&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;swcd (unknown version) CFNetwork/1128.0.1 Darwin/19.6.0"&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;GoogleStackdriverMonitoring-UptimeChecks(&lt;A href="https://cloud.google.com/monitoring" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;https://cloud.google.com/monitoring&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 26 Nov 2020 01:32:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530929#M149978</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-11-26T01:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help on rex command - User agent</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530930#M149979</link>
      <description>&lt;P&gt;as per my understanding, this will be difficult or even impossible on a single rex query.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sooo, before the rex query part, you have to do some if or case statements and find out what user-agent is, and then rex queries for each userAgent and then final calcuations and fields/table.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;base search | eval userAgent = if or case statements
|rex &amp;lt;for trident userAgent&amp;gt; 
|rex &amp;lt;for userAgentX&amp;gt;
|final table&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can select one userAgent, then, we can help you on the SPL query, then, you can continue for remaining userAgents.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;PS - your karma points will be my 2 cents!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 01:42:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530930#M149979</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-11-26T01:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help on rex command - User agent</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530931#M149980</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am unable to attach any screen shot or image.&lt;/P&gt;&lt;P&gt;Could you please give me some input how to upload screenshot.&lt;/P&gt;&lt;P&gt;Thank s&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 01:43:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530931#M149980</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-11-26T01:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help on rex command - User agent</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530932#M149981</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am sorry bit confused, could you please help me with one and i will the try the rest.&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 02:37:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530932#M149981</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-11-26T02:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help on rex command - User agent</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530939#M149983</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226870"&gt;@jaibalaraman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to identify distinct useragent formats to develop regex which will match 100% events.&lt;/P&gt;&lt;P&gt;For example if you look at below two events:&lt;/P&gt;&lt;P&gt;Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko&lt;BR /&gt;Mozilla/5.0 (Linux; Android 8.1.0; CPH1851) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Mobile Safari/537.36&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thambisetty_0-1606370786684.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12066i48398BB09FF66B6E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="thambisetty_0-1606370786684.png" alt="thambisetty_0-1606370786684.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you don't have same fields you have mentioned in your regex for the second event above.&lt;/P&gt;&lt;P&gt;If one regex is not going to match 100% events then you might need to create os1,os2 and then you need to coalesce all fields into&amp;nbsp; one field "os". you need to do same thing for other fields as well.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 06:06:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-some-help-on-rex-command-User-agent/m-p/530939#M149983</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-11-26T06:06:35Z</dc:date>
    </item>
  </channel>
</rss>

