<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to write a regular expression for extracting OS version number from User Agent in my sample data? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324675#M96828</link>
    <description>&lt;P&gt;How do we write a regular expression to extract a OS version from the User Agent considering the fact that UserAgent format is not always consistent? I searched this forum, and found there was similar thread where a Splunk App was suggested to user. However I am regular user, and my Splunk admin doesn't allow me the permission to install any Splunk app. Is there a way I can write regular expression to extract this info as this is present in the UserAgent?&lt;/P&gt;

&lt;P&gt;Sample: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14D27
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 11 Apr 2017 16:15:39 GMT</pubDate>
    <dc:creator>pradjswl</dc:creator>
    <dc:date>2017-04-11T16:15:39Z</dc:date>
    <item>
      <title>How to write a regular expression for extracting OS version number from User Agent in my sample data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324675#M96828</link>
      <description>&lt;P&gt;How do we write a regular expression to extract a OS version from the User Agent considering the fact that UserAgent format is not always consistent? I searched this forum, and found there was similar thread where a Splunk App was suggested to user. However I am regular user, and my Splunk admin doesn't allow me the permission to install any Splunk app. Is there a way I can write regular expression to extract this info as this is present in the UserAgent?&lt;/P&gt;

&lt;P&gt;Sample: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14D27
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 11 Apr 2017 16:15:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324675#M96828</guid>
      <dc:creator>pradjswl</dc:creator>
      <dc:date>2017-04-11T16:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a regular expression for extracting OS version number from User Agent in my sample data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324676#M96829</link>
      <description>&lt;P&gt;As you say, "UserAgent format is not always consistent." Please provide more than one example string that you feel you need to extract from. If you have 20 significantly differing formats, please provide a good number of them as examples.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 16:27:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324676#M96829</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-04-11T16:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a regular expression for extracting OS version number from User Agent in my sample data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324677#M96830</link>
      <description>&lt;P&gt;ty &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/120445"&gt;@cpetterborg&lt;/a&gt; for your response.&lt;/P&gt;

&lt;P&gt;These are the sample of User agent&lt;/P&gt;

&lt;P&gt;Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14D27&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (Linux; Android 7.0; SAMSUNG-SM-G930A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.132 Mobile Safari/537.36&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (iPhone; CPU iPhone OS 10_3_1 like Mac OS X) AppleWebKit/603.1.30 (KHTML, like Gecko) Mobile/14E304&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (Linux; Android 7.0; SAMSUNG-SM-G935A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.132 Mobile Safari/537.36&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (iPad; CPU OS 10_3_1 like Mac OS X) AppleWebKit/603.1.30 (KHTML, like Gecko) Mobile/14E304&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Version/10.0 Mobile/14D27 Safari/602.1&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (Linux; Android 6.0.1; SAMSUNG-SM-G920A Build/MMB29K; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.132 Mobile Safari/537.36&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (Linux; Android 7.0; LG-H820 Build/NRD90U; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.132 Mobile Safari/537.36&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (Linux; Android 6.0.1; SAMSUNG-SM-G935A Build/MMB29M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.132 Mobile Safari/537.36&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (iPad; CPU OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Version/10.0 Mobile/14D27 Safari/602.1&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (iPhone; CPU iPhone OS 10_3_1 like Mac OS X) AppleWebKit/603.1.30 (KHTML, like Gecko) Version/10.0 Mobile/14E304 Safari/602.1&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (iPhone; CPU iPhone OS 10_3 like Mac OS X) AppleWebKit/603.1.30 (KHTML, like Gecko) Mobile/14E277&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (iPad; CPU OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14D27 &lt;BR /&gt;
Mozilla/5.0 (iPhone; CPU iPhone OS 10_1_1 like Mac OS X) AppleWebKit/602.2.14 (KHTML, like Gecko) Mobile/14B100&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (iPhone; CPU iPhone OS 9_3_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Mobile/13F69&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (iPhone; CPU iPhone OS 10_0_2 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) Mobile/14A456&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (Windows NT 6.1; rv:41.0) Gecko/20100101 Firefox/41.0&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (Linux; Android 6.0.1; SAMSUNG-SM-G900A Build/MMB29M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.132 Mobile Safari/537.36&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (Linux; Android 6.0.1; SAMSUNG-SM-N920A Build/MMB29K; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.132 Mobile Safari/537.36&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (iPhone; CPU iPhone OS 10_2 like Mac OS X) AppleWebKit/602.3.12 (KHTML, like Gecko) Mobile/14C92&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (Linux; Android 6.0.1; SAMSUNG-SM-G928A Build/MMB29K; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.132 Mobile Safari/537.36&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (Linux; Android 6.0.1; SM-N920T Build/MMB29K; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/55.0.2883.91 Mobile Safari/537.36&lt;BR /&gt;&lt;BR /&gt;
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0 &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:38:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324677#M96830</guid>
      <dc:creator>pradjswl</dc:creator>
      <dc:date>2020-09-29T13:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a regular expression for extracting OS version number from User Agent in my sample data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324678#M96831</link>
      <description>&lt;P&gt;Does this give you some information that you can use, and if so, what info is of most use to you?:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;yoursearch&amp;gt; | rex "\((?P&amp;lt;osinfo&amp;gt;[^\)]+)\)" | rex field=osinfo "(?P&amp;lt;os&amp;gt;[^;]+);(?P&amp;lt;vers&amp;gt;[^;]+)(;(?P&amp;lt;etc&amp;gt;[^;]+))?" | stats count by os, vers
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 11 Apr 2017 16:52:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324678#M96831</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-04-11T16:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a regular expression for extracting OS version number from User Agent in my sample data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324679#M96832</link>
      <description>&lt;P&gt;I am validating in regex101.com , but it desont return any result. Are you able to get the result ? I am checking for 1st sample Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14D27 .&lt;BR /&gt;
OS version in this case is 10_2_1. If you are getting the right result, could you please share the screen shot too ?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324679#M96832</guid>
      <dc:creator>pradjswl</dc:creator>
      <dc:date>2020-09-29T13:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a regular expression for extracting OS version number from User Agent in my sample data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324680#M96833</link>
      <description>&lt;P&gt;UserAgent has different format for iOS &amp;amp; Andorid as we can see below,&lt;/P&gt;

&lt;P&gt;Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/602.4.6 (KHTML, like Gecko) Mobile/14D27&lt;/P&gt;

&lt;P&gt;Mozilla/5.0 (Linux; Android 7.0; SAMSUNG-SM-G930A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 &lt;/P&gt;

&lt;P&gt;I would like to extract them as "iPhone OS 10_2_1" &amp;amp; "Android 7.0" , would that be possible ? I am struggling to put OR condition where it would check different format based on iOS &amp;amp; Andoird&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:38:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324680#M96833</guid>
      <dc:creator>pradjswl</dc:creator>
      <dc:date>2020-09-29T13:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a regular expression for extracting OS version number from User Agent in my sample data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324681#M96834</link>
      <description>&lt;P&gt;I brought your data (the example lines) into my local machine and did the field extractions inside of Splunk, so it worked fine for me.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://app.box.com/s/nms71me6c1xiwytbneidbybhomrvdlv1" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 20:23:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324681#M96834</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-04-11T20:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a regular expression for extracting OS version number from User Agent in my sample data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324682#M96835</link>
      <description>&lt;P&gt;In regex101 you can use the following to get the first two fields extracted (using multiline):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;\((?P&amp;lt;os&amp;gt;[^;]+);(?P&amp;lt;vers&amp;gt;[^;)]+).*$
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Does that give you what you want from the data? or is there more that you need to use?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 20:34:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324682#M96835</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-04-11T20:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a regular expression for extracting OS version number from User Agent in my sample data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324683#M96836</link>
      <description>&lt;P&gt;This works great. &lt;/P&gt;

&lt;P&gt;PS1 : I dont see an option to accept this as answer for this thread.&lt;BR /&gt;
PS 2: I would raise a new thread "How to create a extracted filed using regex on existing field" ? By default regex uses _raw field in the field extractor. I dont want to use regex as part of the query but I want a field to be created in the event/app like calculated filed so it always stay as new field rather than specifying in the search query.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 21:33:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324683#M96836</guid>
      <dc:creator>pradjswl</dc:creator>
      <dc:date>2017-04-11T21:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a regular expression for extracting OS version number from User Agent in my sample data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324684#M96837</link>
      <description>&lt;P&gt;Now you can accept this answer. &lt;/P&gt;

&lt;P&gt;For your other question, just start a new question, since additional questions within a question are highly discouraged. It will get answered.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 21:39:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-regular-expression-for-extracting-OS-version/m-p/324684#M96837</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-04-11T21:39:56Z</dc:date>
    </item>
  </channel>
</rss>

