<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to  obtain output using REX command ( User Agent) in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533535#M150759</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;First , I would like to thank everyone in this community who guided and helped me a lot.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now i have a problem executing the below rex command&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;User agent&lt;/STRONG&gt; -&amp;nbsp;Mozilla/5.0 (Linux; Android 8.1.0; ASUS_X00ID) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.101 Mobile Safari/537.36&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;REX&lt;/STRONG&gt; -&amp;nbsp;\(\w+;\s+(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+[^ ]+)\s(?&amp;lt;device_brand_model&amp;gt;\w+).\s(?&amp;lt;browser_engine&amp;gt;\w+)\D(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s+\(.+\)\s+(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)\s+(?&amp;lt;hardware_type&amp;gt;\w+)&lt;/P&gt;&lt;P&gt;I tested the rex command in " &lt;STRONG&gt;regex101.com&lt;/STRONG&gt; and it match the information correction and i getting the output as expected.&amp;nbsp; However when i tried executing the same command in Splunk i am getting a blank screen in the Statistics view.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Dec 2020 03:34:02 GMT</pubDate>
    <dc:creator>jaibalaraman</dc:creator>
    <dc:date>2020-12-18T03:34:02Z</dc:date>
    <item>
      <title>Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533535#M150759</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;First , I would like to thank everyone in this community who guided and helped me a lot.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now i have a problem executing the below rex command&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;User agent&lt;/STRONG&gt; -&amp;nbsp;Mozilla/5.0 (Linux; Android 8.1.0; ASUS_X00ID) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.101 Mobile Safari/537.36&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;REX&lt;/STRONG&gt; -&amp;nbsp;\(\w+;\s+(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+[^ ]+)\s(?&amp;lt;device_brand_model&amp;gt;\w+).\s(?&amp;lt;browser_engine&amp;gt;\w+)\D(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s+\(.+\)\s+(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)\s+(?&amp;lt;hardware_type&amp;gt;\w+)&lt;/P&gt;&lt;P&gt;I tested the rex command in " &lt;STRONG&gt;regex101.com&lt;/STRONG&gt; and it match the information correction and i getting the output as expected.&amp;nbsp; However when i tried executing the same command in Splunk i am getting a blank screen in the Statistics view.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 03:34:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533535#M150759</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-12-18T03:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533536#M150760</link>
      <description>&lt;P&gt;When i execute the command i see on result under Events however when i tried the output using table command i see only the header and blank screen. Also i can see only "&lt;STRONG&gt;browser_version, os_version&lt;/STRONG&gt;" in the selected field&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a screen shot unfortunately i am unable to attach to explain more about my issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 03:42:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533536#M150760</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-12-18T03:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533540#M150761</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226870"&gt;@jaibalaraman&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;to add a screenshot to your message you can drag and drop the file in the editing box or browse the file to attach, see the below box.&lt;/P&gt;&lt;P&gt;About the regex, let me understand:&lt;/P&gt;&lt;P&gt;your tested your regex in regex101.com then in Splunk you see the first two fields in the interesting fields but not in the table, is it correct?&lt;/P&gt;&lt;P&gt;i think that you already tested your search in Verbose Mode.&lt;/P&gt;&lt;P&gt;Anyway, try to move the fields in Selected Fields.&lt;/P&gt;&lt;P&gt;If you don't see some of the files, maybe they are too few to be listed in Interesting Fields, so try to add to your search nomefile=*, in this way you're sure that the fiekld is extracted and you can add it to Selected Fields.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 06:45:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533540#M150761</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-12-18T06:45:31Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533761#M150836</link>
      <description>&lt;P&gt;&lt;BR /&gt;1 - your tested your regex in regex101.com then in Splunk you see the first two fields in the interesting fields but not in the table.&lt;/P&gt;&lt;P&gt;Yes, no error in splunk, but the table is showing blank data. From the below list only 2 two fields appear in interesting field&lt;/P&gt;&lt;P&gt;browser_version, os_version&lt;/P&gt;&lt;P&gt;not listed fields are os_family, device_brand_model,browser_engine,browser,Browser_enginer_version,hardware_type&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 19:37:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533761#M150836</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-12-21T19:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533762#M150837</link>
      <description>&lt;P&gt;2 - i think that you already tested your search in Verbose Mode.&lt;/P&gt;&lt;P&gt;Yes, i have tested in verbose mode&lt;/P&gt;&lt;P&gt;3- try to move the fields in Selected Fields.&lt;/P&gt;&lt;P&gt;If you don't see some of the files, maybe they are too few to be listed in Interesting Fields, so try to add to your search nomefile=*, in this way you're sure that the field&lt;/P&gt;&lt;P&gt;is extracted and you can add it to Selected Fields.&lt;/P&gt;&lt;P&gt;Sorry i don't understand, could you please guide how to do.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 19:41:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533762#M150837</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-12-21T19:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533763#M150838</link>
      <description>&lt;P&gt;Yes, i tried exactly same but i am getting error msg as your file format not support.&lt;/P&gt;&lt;P&gt;I tried, PNG, jpeg, jpg, PowerPoint still same also when i tried alternate option like browse and select the img are not listed ( All files ).&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 19:44:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533763#M150838</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-12-21T19:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533791#M150846</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226870"&gt;@jaibalaraman&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;maybe you have few values so Splunk doesn't put them in interesting fields.&lt;/P&gt;&lt;P&gt;So try running your search in this way:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;your_search device_brand_model=*&lt;/LI-CODE&gt;&lt;P&gt;in this way, if you correctly extracted the "&lt;SPAN&gt;device_brand_model" field, you'll have it in interesting fields and you can move it in Selected fields.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In this way you'll see it even if you have few values.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;then repeat this procedure also fo the other missing fields.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 07:13:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533791#M150846</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-12-22T07:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533793#M150847</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226870"&gt;@jaibalaraman&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it's strange: there isn't any requirement on file format, only dimension less than 5 MB.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gcusello_0-1608621412921.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12341i9A2A12EF97D5DE7D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="gcusello_0-1608621412921.png" alt="gcusello_0-1608621412921.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 07:17:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533793#M150847</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-12-22T07:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533883#M150876</link>
      <description />
      <pubDate>Tue, 22 Dec 2020 20:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533883#M150876</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-12-22T20:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533907#M150881</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have tried the "device_brand_model=*" in the SPL search and i getting the below error message . I am sure that i have done something wrong.&lt;/P&gt;&lt;P&gt;Could you please guide&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;" Error in 'rex' command: Encountered the following error while compiling the regex '\(\w+;\s+(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+[^ ]+)\s(?&amp;lt;device_brand_model=*&amp;gt;\w+).\s(?&amp;lt;browser_engine&amp;gt;\w+)\D(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s+\(.+\)\s+(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)\s+(?&amp;lt;hardware_type&amp;gt;\w+)': Regex: syntax error in subpattern name (missing terminator) "&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 02:38:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533907#M150881</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-12-23T02:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533920#M150884</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226870"&gt;@jaibalaraman&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;could you share your search?&lt;/P&gt;&lt;P&gt;The error message says that's a formal error in the regex (quotes or parenthesys).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 07:27:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533920#M150884</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-12-23T07:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533996#M150910</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, please find below&lt;/P&gt;&lt;P&gt;"&amp;nbsp;|rex"\(\w+;\s+(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+[^ ]+)\s(?&amp;lt;device_brand_model=*&amp;gt;\w+).\s(?&amp;lt;browser_engine&amp;gt;\w+)\D(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s+\(.+\)\s+(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)\s+(?&amp;lt;hardware_type&amp;gt;\w+)" device_brand_model=*"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1608756903583.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12353i63CE8371EAB72607/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1608756903583.png" alt="jaibalaraman_0-1608756903583.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 20:55:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533996#M150910</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-12-23T20:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533999#M150911</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now i find the way to add image, please find below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1608756990105.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12354iB354ACD9BD5C8B77/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1608756990105.png" alt="jaibalaraman_0-1608756990105.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_1-1608756999858.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12355i8A10EC33D10FB1A7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_1-1608756999858.png" alt="jaibalaraman_1-1608756999858.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 20:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/533999#M150911</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-12-23T20:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/534029#M150923</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226870"&gt;@jaibalaraman&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in the regex you shared there's an error (present also in the first image but not in the second:&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;device_brand_model=*&amp;gt;  it's wrong
&amp;lt;device_brand_model&amp;gt; it's correct&lt;/LI-CODE&gt;&lt;P&gt;then after there's a single dot, use:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;.*&lt;/LI-CODE&gt;&lt;P&gt;Then at the end of the shared regex (and in the first image) there's an error that probably it's a copy error:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;device_brand_model=*"&lt;/LI-CODE&gt;&lt;P&gt;Anyway, this should be the correct regex:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "\(\w+;\s+(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+[^ ]+);\s(?&amp;lt;device_brand_model&amp;gt;\w+).*\s(?&amp;lt;browser_engine&amp;gt;\w+)\D(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s+\(.+\)\s+(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)\s+(?&amp;lt;hardware_type&amp;gt;\w+)"&lt;/LI-CODE&gt;&lt;P&gt;That you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/M0V69d/1/" target="_blank"&gt;https://regex101.com/r/M0V69d/1/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2020 09:20:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/534029#M150923</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-12-24T09:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/534033#M150924</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226870"&gt;@jaibalaraman&lt;/a&gt;, can you please try using fieldname that contains UserAgent data for rex command. AWS http request log has this value as second value. That is why I put &lt;STRONG&gt;httpRequest.headers{1}.value&lt;/STRONG&gt; , please check that field has UserAgent data otherwise correct the field index.&lt;/P&gt;&lt;P&gt;Also you can put your dedup command before rex.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index= aws
| dedup clientIp
| rex field=httpRequest.headers{1}.value "\(\w+;\s+(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+[^ ]+);\s(?&amp;lt;device_brand_model&amp;gt;\w+).*\s(?&amp;lt;browser_engine&amp;gt;\w+)\D(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s+\(.+\)\s+(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)\s+(?&amp;lt;hardware_type&amp;gt;\w+)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2020 10:08:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/534033#M150924</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2020-12-24T10:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/534428#M151020</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for the late response&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, i have tried the REX command , but i am getting some error message&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1609298975538.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12392i15ADFE7964C744E7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1609298975538.png" alt="jaibalaraman_0-1609298975538.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also when i run my original REX command , now i can see all filed in the selected filed. I dont know what happen now i can see all the fields,&lt;/P&gt;&lt;P&gt;REX -&amp;nbsp;"\(\w+;\s+(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+[^ ]+)\s(?&amp;lt;device_brand_model&amp;gt;\w+).\s(?&amp;lt;browser_engine&amp;gt;\w+)\D(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s+\(.+\)\s+(?&amp;lt;browser&amp;gt;\w+).(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)\s+(?&amp;lt;hardware_type&amp;gt;\w+)"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_1-1609299106121.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12393i0161F022DFCCFEFF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_1-1609299106121.png" alt="jaibalaraman_1-1609299106121.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_2-1609299153389.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12394i09040894D0D338F5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_2-1609299153389.png" alt="jaibalaraman_2-1609299153389.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However still i can see only blank table&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_3-1609299392616.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12395i8CE399360DDDE7E2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_3-1609299392616.png" alt="jaibalaraman_3-1609299392616.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 03:36:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/534428#M151020</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2020-12-30T03:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to  obtain output using REX command ( User Agent)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/534476#M151040</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226870"&gt;@jaibalaraman&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first, check if the fields you see in interesting fields are present in all the events or not (in the fields panel there's the perc of events with that field).&lt;/P&gt;&lt;P&gt;probably you extract few values and only putting those fields in "Selected fields" you can see them.&lt;/P&gt;&lt;P&gt;Anyway, try to add to your search (after the rex command) the command:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search os_version=*&lt;/LI-CODE&gt;&lt;P&gt;if in the way you see results, the problem is that you extract too few values.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 13:11:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-obtain-output-using-REX-command-User-Agent/m-p/534476#M151040</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-12-30T13:11:11Z</dc:date>
    </item>
  </channel>
</rss>

