Splunk Search

Regex - Browser search

leberhart
New Member

I need to be able to find our users that are using the Safari browser. The user agent string looks something like this:

"Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30"

I believe the regex string to be something like this: ^Mozilla/.*Safari.

So how to I properly form the search?

Side note: I have a whole set of regex to set the browser type based on the user agent string. Is this best accomplished with a lookup?

Tags (3)
0 Karma

Simeon
Splunk Employee
Splunk Employee

A search for all users of Safari should just be directed to your web access logs and the Safari or AppleWebKit keyword:

sourcetype=access_combined Safari AppleWebKit

Alternatively, you probably want to extract the user agent string and group by that. To do that, you should use the built in extractions for iis or apache. If you are using apache, simply classify your sourcetype for these logs as access_combined.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...