<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User agent browser type display issue in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/550810#M156305</link>
    <description>&lt;P&gt;To properly help you, we'd need to see examples of the User_Agent strings you're trying to match.&lt;/P&gt;&lt;P&gt;Have you gone to regex101.com to confirm your regular expressions work with the data you have?&lt;/P&gt;</description>
    <pubDate>Tue, 11 May 2021 12:45:33 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-05-11T12:45:33Z</dc:date>
    <item>
      <title>User agent browser type display issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/550746#M156285</link>
      <description>&lt;P&gt;Hi team&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried the below spl eval command&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1620353060498.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14075i1D45EF4A17A3762B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1620353060498.png" alt="jaibalaraman_0-1620353060498.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;index=aws Website="*"&lt;BR /&gt;| stats count(eval(match(User_Agent, "Firefox"))) as "Firefox", count(eval(match(User_Agent, "Chrome"))) as "Chrome", count(eval(match(User_Agent, "Safari"))) as "Safari", count(eval(match(User_Agent, "MSIE"))) as "IE", count(eval(match(User_Agent, "Trident"))) as "Trident", count(eval(NOT match(User_Agent, "Chrome|Firefox|Safari|MSIE|Trident"))) as "Other" | transpose | sort by User_Agent&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When i use this to my Splunk&amp;nbsp;script, it gives all data to "Other". Firefox=0, Chrome=0 IE=0,&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 02:08:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/550746#M156285</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2021-05-07T02:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: User agent browser type display issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/550810#M156305</link>
      <description>&lt;P&gt;To properly help you, we'd need to see examples of the User_Agent strings you're trying to match.&lt;/P&gt;&lt;P&gt;Have you gone to regex101.com to confirm your regular expressions work with the data you have?&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 12:45:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/550810#M156305</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-05-11T12:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: User agent browser type display issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/551158#M156397</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, i tried Regex it working for individual browser like below sample ,&amp;nbsp;&lt;/P&gt;&lt;TABLE width="2073"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="85"&gt;Device&lt;/TD&gt;&lt;TD width="1051"&gt;User agent&lt;/TD&gt;&lt;TD width="937"&gt;Rex command&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Iphone&lt;/TD&gt;&lt;TD&gt;Mozilla/5.0 (iPhone; CPU iPhone OS 14_2_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.1 Mobile/15E148 Safari/604.1&lt;/TD&gt;&lt;TD width="937"&gt;\((?&amp;lt;hardware_type&amp;gt;\w+);\s+[^ ]+\s(?&amp;lt;os_family&amp;gt;\w+\s[^ ]+)\s+(?&amp;lt;os_version&amp;gt;\w+)\s[^ ]+\s[^ ]+\s\w+\s\w.\s(?&amp;lt;browser_engine&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s+\(.+\)\s+(?&amp;lt;browser_version&amp;gt;\w+\/[^ ]+)\s+\w+\/\w+\s(?&amp;lt;browser&amp;gt;\w+)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Ipad&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Mozilla/5.0 (iPad; CPU OS 12_4_9 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Mobile/15E148 Safari/604.1&lt;/TD&gt;&lt;TD width="937"&gt;\((?&amp;lt;hardware_type&amp;gt;\w+);\s+[^ ]+\s(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+)\s[^ ]+\s[^ ]+\s\w+\s\w.\s(?&amp;lt;browser_engine&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s\(.+\)\s+(?&amp;lt;browser_version&amp;gt;\w+\/[^ ]+)\s\w+\/\w+\s(?&amp;lt;browser&amp;gt;\w+)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Window&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36 Edge/87.0.664.66&lt;/TD&gt;&lt;TD width="937"&gt;\((?&amp;lt;os_family&amp;gt;\w+)\s+\w+\s+(?&amp;lt;os_version&amp;gt;[^;]+)[^\)]+\)\s(?&amp;lt;browser_egnine&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s\(.+\)\s[^ ]+\s[^ ]+\s(?&amp;lt;browser&amp;gt;\w+)\/(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Macintosh&lt;/TD&gt;&lt;TD&gt;Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.2 Safari/605.1.15"&lt;/TD&gt;&lt;TD width="937"&gt;\((?&amp;lt;hardware_type&amp;gt;\w+);\s\w+\s+(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+\s[^ ]+\s[^ ]+)\s(?&amp;lt;browser_enginer&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s\(.+\)\s(?&amp;lt;browser_version&amp;gt;\w+\/[^ ]+)\s(?&amp;lt;browser&amp;gt;\w+)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Android / Vodoafone\&lt;/TD&gt;&lt;TD&gt;Mozilla/5.0 (Linux; Android 10; SM-A217F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.101 Mobile Safari/537.36&lt;/TD&gt;&lt;TD width="937"&gt;\(\w+;\s(?&amp;lt;os_family&amp;gt;\w+)\s(?&amp;lt;os_version&amp;gt;\w+);\s(?&amp;lt;device_brand_model&amp;gt;\w+[^ ]+)\s(?&amp;lt;browser_enginer&amp;gt;\w+)\/(?&amp;lt;brow_engine_version&amp;gt;\w+[^ ]+)\s\(.+\)\s(?&amp;lt;browser&amp;gt;\w+)\/(?&amp;lt;browser_version&amp;gt;\w+[^ ]+)\s(?&amp;lt;hardware_type&amp;gt;\w+)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 11 May 2021 04:25:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/551158#M156397</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2021-05-11T04:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: User agent browser type display issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/551159#M156398</link>
      <description>&lt;P&gt;However, i am trying to get only the&amp;nbsp; browser count from the spl query&lt;/P&gt;&lt;P&gt;Mozilla - 400&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chrome - 500&amp;nbsp;&lt;/P&gt;&lt;P&gt;IE - 899&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 04:26:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/551159#M156398</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2021-05-11T04:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: User agent browser type display issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/551237#M156421</link>
      <description>&lt;P&gt;May I suggest the TA-user-agents app (&lt;A href="https://splunkbase.splunk.com/app/1843/" target="_blank"&gt;https://splunkbase.splunk.com/app/1843/&lt;/A&gt;) rather than re-inventing the wheel?&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 13:09:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/551237#M156421</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-05-11T13:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: User agent browser type display issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/552477#M156818</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for the late responce&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately TA - user agent app is not support for Splunk cloud user&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_1-1621563619414.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14248i92786EA5ED21AED9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_1-1621563619414.png" alt="jaibalaraman_1-1621563619414.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also , TA Browscap app is also&amp;nbsp; not supported in Splunk 8.0 version&lt;/P&gt;&lt;P&gt;So could you please on this..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 02:22:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/552477#M156818</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2021-05-21T02:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: User agent browser type display issue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/552561#M156853</link>
      <description>&lt;P&gt;This is rather challenging to do in SPL, which explains why the TAs use external commands to parse the URLs.&amp;nbsp; Perhaps reviewing the TAs will give you ideas on how to accomplish your goal.&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 14:31:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-browser-type-display-issue/m-p/552561#M156853</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-05-21T14:31:25Z</dc:date>
    </item>
  </channel>
</rss>

