Getting Data In

How to break events while indexing

moohkhol
New Member

Hi,

I have events which logging user agents information,

USR_AGNT="Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

In the above log events, we have browser information as well as OS information, How i can transform it while indexing into two different key such OS_INFO (operating system related information) and BRW_INFO (Browser related information) under USR_AGNT.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You can extract that information at search time as you normally would for any field. See http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Aboutfields for more.

Note, breaking events is a different thing - see http://docs.splunk.com/Documentation/Splunk/latest/Data/Indexmulti-lineevents for that.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...