<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User agent Android 10 &amp;amp; IOS 14  - Difficult in extracting Field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/User-agent-Android-10-amp-IOS-14-Difficult-in-extracting-Field/m-p/553770#M157230</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to extract field from the user agent details like ( Operating system, Software, Software version, Software type, Os version, Hardware type)&amp;nbsp;&lt;/P&gt;&lt;P&gt;However i am finding some difficulty extracting the field . For example Operation system in Android, IOS &amp;amp; desktop are in the different field which highlighted below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Android user&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&amp;nbsp;&lt;SPAN class="t"&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Linux&lt;/SPAN&gt;&lt;SPAN&gt;;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#33CCCC"&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;Android&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;10&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;SAMSUNG&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;SM-T590&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;AppleWebKit/537.36&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;SamsungBrowser / 12.1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Chrome/79.0.3945.136&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Safari/537.36&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;Iphone user&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&amp;nbsp;&lt;SPAN class="t"&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;iPhone&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;CPU&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;iPhone&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#33CCCC"&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;OS&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;14_1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Mac&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;OS&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;X&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;AppleWebKit/605.1.15&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Version/14.0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Mobile/15E148&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Safari/604.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;can someone help me how do extract field from the above user agent&amp;nbsp;&lt;/P&gt;&lt;P&gt;Software, Software version, Hardware type, Operation System,&amp;nbsp; Operating system name , Operation system version.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;View more huy dung service :&amp;nbsp;&lt;A href="https://huydungmobile.com/thay-pin-iphone-8-plus/" target="_self"&gt;thay pin iPhone 8 Plus&lt;/A&gt; - và dịch vụ &lt;A href="https://huydungmobile.com/sua-chua-iphone/thay-mat-kinh-iphone/" target="_self"&gt;ép kính iPhone&lt;/A&gt; lấy liền&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jul 2021 20:59:33 GMT</pubDate>
    <dc:creator>advidlan</dc:creator>
    <dc:date>2021-07-01T20:59:33Z</dc:date>
    <item>
      <title>User agent Android 10 &amp; IOS 14  - Difficult in extracting Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-Android-10-amp-IOS-14-Difficult-in-extracting-Field/m-p/553770#M157230</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to extract field from the user agent details like ( Operating system, Software, Software version, Software type, Os version, Hardware type)&amp;nbsp;&lt;/P&gt;&lt;P&gt;However i am finding some difficulty extracting the field . For example Operation system in Android, IOS &amp;amp; desktop are in the different field which highlighted below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Android user&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&amp;nbsp;&lt;SPAN class="t"&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Linux&lt;/SPAN&gt;&lt;SPAN&gt;;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#33CCCC"&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;Android&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;10&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;SAMSUNG&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;SM-T590&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;AppleWebKit/537.36&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;SamsungBrowser / 12.1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Chrome/79.0.3945.136&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Safari/537.36&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;Iphone user&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&amp;nbsp;&lt;SPAN class="t"&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;iPhone&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;CPU&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;iPhone&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#33CCCC"&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;OS&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;14_1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Mac&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;OS&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;X&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;AppleWebKit/605.1.15&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;like&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Version/14.0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Mobile/15E148&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Safari/604.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;can someone help me how do extract field from the above user agent&amp;nbsp;&lt;/P&gt;&lt;P&gt;Software, Software version, Hardware type, Operation System,&amp;nbsp; Operating system name , Operation system version.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;View more huy dung service :&amp;nbsp;&lt;A href="https://huydungmobile.com/thay-pin-iphone-8-plus/" target="_self"&gt;thay pin iPhone 8 Plus&lt;/A&gt; - và dịch vụ &lt;A href="https://huydungmobile.com/sua-chua-iphone/thay-mat-kinh-iphone/" target="_self"&gt;ép kính iPhone&lt;/A&gt; lấy liền&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 20:59:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-Android-10-amp-IOS-14-Difficult-in-extracting-Field/m-p/553770#M157230</guid>
      <dc:creator>advidlan</dc:creator>
      <dc:date>2021-07-01T20:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: User agent Android 10 &amp; IOS 14  - Difficult in extracting Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-Android-10-amp-IOS-14-Difficult-in-extracting-Field/m-p/553773#M157231</link>
      <description>&lt;P&gt;User agent is not well defined - you could try looking at other posts on the subject, for example&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535003?search-action-id=33249106577&amp;amp;search-result-uid=535003" target="_blank"&gt;https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/535003?search-action-id=33249106577&amp;amp;search-result-uid=535003&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 05:22:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-Android-10-amp-IOS-14-Difficult-in-extracting-Field/m-p/553773#M157231</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-01T05:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: User agent Android 10 &amp; IOS 14  - Difficult in extracting Field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-agent-Android-10-amp-IOS-14-Difficult-in-extracting-Field/m-p/553777#M157232</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234963"&gt;@advidlan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the hints of&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;guide you to the best approach to the problem.&lt;/P&gt;&lt;P&gt;This is a sample of this approach:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(Linux;|iPhone;\s+CPU\s+iPhone)\s+(?&amp;lt;os_versione&amp;gt;\w+\s+\w+)"&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/km2EXB/1" target="_blank"&gt;https://regex101.com/r/km2EXB/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 06:00:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-agent-Android-10-amp-IOS-14-Difficult-in-extracting-Field/m-p/553777#M157232</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-01T06:00:08Z</dc:date>
    </item>
  </channel>
</rss>

