<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Extracting fields doesn't extract the same information in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-doesn-t-extract-the-same-information/m-p/604472#M210255</link>
    <description>&lt;P&gt;I'm sorting through web traffic and I'm trying to extract what device users are using from the user agent. However, when I have highlighted the device and check the preview, it has highlighted some different devices like Windows, Macintosh, Linux.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it has also highlighted a lot of random strings of text that definitely aren't devices, and when I've looked through these, I can clearly see the device in that user agent that hasn't been highlighted.&lt;/P&gt;&lt;P&gt;Is there a way to make sure devices are being highlighted to be extracted and now random strings of text etc?&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2022 16:01:37 GMT</pubDate>
    <dc:creator>jhilton90</dc:creator>
    <dc:date>2022-07-05T16:01:37Z</dc:date>
    <item>
      <title>Extracting fields doesn't extract the same information</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-doesn-t-extract-the-same-information/m-p/604472#M210255</link>
      <description>&lt;P&gt;I'm sorting through web traffic and I'm trying to extract what device users are using from the user agent. However, when I have highlighted the device and check the preview, it has highlighted some different devices like Windows, Macintosh, Linux.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it has also highlighted a lot of random strings of text that definitely aren't devices, and when I've looked through these, I can clearly see the device in that user agent that hasn't been highlighted.&lt;/P&gt;&lt;P&gt;Is there a way to make sure devices are being highlighted to be extracted and now random strings of text etc?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 16:01:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-doesn-t-extract-the-same-information/m-p/604472#M210255</guid>
      <dc:creator>jhilton90</dc:creator>
      <dc:date>2022-07-05T16:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields doesn't extract the same information</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-doesn-t-extract-the-same-information/m-p/604474#M210256</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/247446"&gt;@jhilton90&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;are you using custom field extractions or the ones from a TA from Splunkbase?&lt;/P&gt;&lt;P&gt;If custom one, I hint to use the one for your technology from Splunkbase.&lt;/P&gt;&lt;P&gt;If instead you're using a TA from Splunkbase, the only way is to check one by one all the the regex extractions in the TA, but I cannot help you without the indication of what's the tecnology you're using and some sample of your logs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 16:09:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-doesn-t-extract-the-same-information/m-p/604474#M210256</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-05T16:09:32Z</dc:date>
    </item>
  </channel>
</rss>

