<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I search for a particular string in a larger string? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381304#M166649</link>
    <description>&lt;P&gt;Thank you thank you thank you thank you thank you!!!!&lt;/P&gt;

&lt;P&gt;Marry me!&lt;/P&gt;</description>
    <pubDate>Fri, 09 Nov 2018 18:58:44 GMT</pubDate>
    <dc:creator>moizmmz</dc:creator>
    <dc:date>2018-11-09T18:58:44Z</dc:date>
    <item>
      <title>How can I search for a particular string in a larger string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381302#M166647</link>
      <description>&lt;P&gt;I am running the following query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=uplynk slice_played | rex field=_raw "^(?&amp;lt;date&amp;gt;\S*)\s*(?&amp;lt;time&amp;gt;\S*)\s*(?&amp;lt;slice_played&amp;gt;\S*)\s*(?&amp;lt;assetID&amp;gt;\S*)\s*(?&amp;lt;sliceNumber&amp;gt;\S*)\s*(?&amp;lt;isLive&amp;gt;\S*)\s*(?&amp;lt;userIP&amp;gt;\S*)\s*(?&amp;lt;playerUserAgent&amp;gt;\S*)\s*(?&amp;lt;referrerURL&amp;gt;\S*)\s*(?&amp;lt;externalUserID&amp;gt;\S*)\s*(?&amp;lt;sessionID&amp;gt;\S*)\s*(?&amp;lt;playingOwnerID&amp;gt;\S*)\s*(?&amp;lt;channelID&amp;gt;\S*)\s*(?&amp;lt;eventID&amp;gt;\S*)\s*(?&amp;lt;duration&amp;gt;\S*)" | dedup channelID | search isLive=1 | stats values(playerUserAgent)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And I get the following values for the newly created field playerUserAgent:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;-
AppleCoreMedia%20/%201.0.0.12B411%20(iPhone;%20U;%20CPU%20OS%208_1%20like%20Mac%20OS%20X;%20en_us)
AppleCoreMedia/1.0.0.12H606%20(Apple%20TV;%20U;%20CPU%20OS%208_4_2%20like%20Mac%20OS%20X;%20en_us)
AppleCoreMedia/1.0.0.16A404%20(iPad;%20U;%20CPU%20OS%2012_0_1%20like%20Mac%20OS%20X;%20en_us)
AppleCoreMedia/1.0.0.16J602%20(Apple%20TV;%20U;%20CPU%20OS%2012_1%20like%20Mac%20OS%20X;%20en_us)
AppleCoreMedia/1.0.0.18A391%20(Macintosh;%20U;%20Intel%20Mac%20OS%20X%2010_14;%20en_us)
Dalvik/2.1.0%20(Linux;%20U;%20Android%208.0.0;%20SM-J337P%20Build/R16NW)%20FOX%20NOW/3.10.2
Lavf/57.83.100
Mozilla/5.0%20(Linux;%20Android%205.1.1;%20AFTT%20Build/LVY48F;%20wv)%20AppleWebKit/537.36%20(KHTML,%20like%20Gecko)%20Version/4.0%20Chrome/59.0.3071.125%20Mobile%20Safari/537.36
Mozilla/5.0%20(Linux;%20Android%207.1.2;%20AFTN%20Build/NS6255;%20wv)%20AppleWebKit/537.36%20(KHTML,%20like%20Gecko)%20Version/4.0%20Chrome/59.0.3071.125%20Mobile%20Safari/537.36
Mozilla/5.0%20(Windows%20NT%2010.0;%20Win64;%20x64)%20AppleWebKit/537.36%20(KHTML,%20like%20Gecko)%20Chrome/70.0.3538.77%20Safari/537.36
Mozilla/5.0%20(X11;%20Linux%20armv7l)%20AppleWebKit/537.36%20(KHTML,%20like%20Gecko)%20Chrome/66.0.3359.120%20Safari/537.36%20CrKey/1.32.124602
Mozilla/5.0%20(X11;%20Linux%20armv7l)%20AppleWebKit/537.36%20(KHTML,%20like%20Gecko)%20Chrome/69.0.3497.86%20Safari/537.36%20CrKey/1.35.137090
Mozilla/5.0%20(X11;%20Linux%20i686)%20AppleWebKit/537.36%20(KHTML,%20like%20Gecko)%20Chrome/29.0.1547.57%20Safari/537.36
Mozilla/5.0%20(X11;%20Linux%20x86_64;%20rv:28.0)%20Gecko/20100101%20Firefox/28.0
Mozilla/5.0%20(iPhone;%20CPU%20iPhone%20OS%207_1%20like%20Mac%20OS%20X)%20AppleWebKit/537.51.2%20(KHTML,%20like%20Gecko)%20Version/7.0%20Mobile/11D167%20Safari/9537.53%20Witbe
Roku/DVP-8.10%20(048.10E04145A)
Roku/DVP-8.10%20(098.10E04131A)
Roku/DVP-8.10%20(288.10E04155A)
Roku/DVP-8.10%20(558.10E04145A)
Roku/DVP-8.20%20(088.20E04167A)
Roku/DVP-9.0%20(559.00E04052A)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'm aiming to create a new field called 'devicetype' which shows the following:&lt;BR /&gt;
Roku&lt;BR /&gt;
iOS&lt;BR /&gt;
Android   and so on&lt;/P&gt;

&lt;P&gt;So maybe I can use a search match or something..where if I find the word Roku in the string..I can put it under 'Roku'&lt;/P&gt;

&lt;P&gt;Pls help!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 17:39:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381302#M166647</guid>
      <dc:creator>moizmmz</dc:creator>
      <dc:date>2018-11-09T17:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: How can I search for a particular string in a larger string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381303#M166648</link>
      <description>&lt;P&gt;You could do an eval like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eval devicetype = case(like(playerUserAgent, "%Roku%"), "Roku", like(playerUserAgent, "%iOS%"), "iOS", like(playerUserAgent, "%Android%"), "Android", 1=1,"Other") 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 09 Nov 2018 18:23:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381303#M166648</guid>
      <dc:creator>kmaron</dc:creator>
      <dc:date>2018-11-09T18:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: How can I search for a particular string in a larger string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381304#M166649</link>
      <description>&lt;P&gt;Thank you thank you thank you thank you thank you!!!!&lt;/P&gt;

&lt;P&gt;Marry me!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 18:58:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381304#M166649</guid>
      <dc:creator>moizmmz</dc:creator>
      <dc:date>2018-11-09T18:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: How can I search for a particular string in a larger string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381305#M166650</link>
      <description>&lt;P&gt;Did EXACTLY what I wanted!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 18:59:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381305#M166650</guid>
      <dc:creator>moizmmz</dc:creator>
      <dc:date>2018-11-09T18:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: How can I search for a particular string in a larger string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381306#M166651</link>
      <description>&lt;P&gt;you are very welcome!  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 19:06:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381306#M166651</guid>
      <dc:creator>kmaron</dc:creator>
      <dc:date>2018-11-09T19:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: How can I search for a particular string in a larger string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381307#M166652</link>
      <description>&lt;P&gt;What does the % inside the double quotes signify?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 19:27:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381307#M166652</guid>
      <dc:creator>moizmmz</dc:creator>
      <dc:date>2018-11-09T19:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: How can I search for a particular string in a larger string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381308#M166653</link>
      <description>&lt;P&gt;its a wildcard  (much like you're used to using *)&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 19:28:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381308#M166653</guid>
      <dc:creator>kmaron</dc:creator>
      <dc:date>2018-11-09T19:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: How can I search for a particular string in a larger string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381309#M166654</link>
      <description>&lt;P&gt;Cool! thanks..&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 22:04:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-search-for-a-particular-string-in-a-larger-string/m-p/381309#M166654</guid>
      <dc:creator>moizmmz</dc:creator>
      <dc:date>2018-11-09T22:04:46Z</dc:date>
    </item>
  </channel>
</rss>

