Splunk Search

Extracting fields doesn't extract the same information

Path Finder

I'm sorting through web traffic and I'm trying to extract what device users are using from the user agent. However, when I have highlighted the device and check the preview, it has highlighted some different devices like Windows, Macintosh, Linux. 

But it has also highlighted a lot of random strings of text that definitely aren't devices, and when I've looked through these, I can clearly see the device in that user agent that hasn't been highlighted.

Is there a way to make sure devices are being highlighted to be extracted and now random strings of text etc?

Labels (3)
0 Karma


Hi @jhilton90,

are you using custom field extractions or the ones from a TA from Splunkbase?

If custom one, I hint to use the one for your technology from Splunkbase.

If instead you're using a TA from Splunkbase, the only way is to check one by one all the the regex extractions in the TA, but I cannot help you without the indication of what's the tecnology you're using and some sample of your logs.



0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...