Splunk Search

Extract the User-Agent from HTTP request

ashishmgupta
Explorer

Below the excerpt from my HTTP request and I'm trying to get the User-Agent value from it and so far not successful. Will appreciate any help.

This Splunk editor is removing the carriage return and line feed characters so below is the regex101 link.https://regex101.com/r/rdu8yE/1

Also attached is the screenshot of the HTTP request.

 

 

Labels (2)
0 Karma
1 Solution

ashishmgupta
Explorer

looks like 4 backslashes to get two? Below worked. Thank you for your help. 

User-Agent: (?<UserAgent>[^\\\\]*)

View solution in original post

0 Karma

ashishmgupta
Explorer

looks like 4 backslashes to get two? Below worked. Thank you for your help. 

User-Agent: (?<UserAgent>[^\\\\]*)

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Your regex was very close.  This worked for me using the one example:

User-Agent: (?<UserAgent>[^\\]*)
---
If this reply helps you, Karma would be appreciated.

ashishmgupta
Explorer

Error in 'rex' command: Encountered the following error while compiling the regex 'User-Agent: (?<UserAgent>[^\]*)': Regex: missing terminating ] for character class.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

To use backslashes in a regex in SPL you have to escape them.

User-Agent: (?<UserAgent>[^\\\\\\]*)

Yes, that's 6 backslashes to get two.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Splunk Observability Metrics Cost Optimization

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...