Splunk Search

Regex - Browser search

leberhart
New Member

I need to be able to find our users that are using the Safari browser. The user agent string looks something like this:

"Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30"

I believe the regex string to be something like this: ^Mozilla/.*Safari.

So how to I properly form the search?

Side note: I have a whole set of regex to set the browser type based on the user agent string. Is this best accomplished with a lookup?

Tags (3)
0 Karma

Simeon
Splunk Employee
Splunk Employee

A search for all users of Safari should just be directed to your web access logs and the Safari or AppleWebKit keyword:

sourcetype=access_combined Safari AppleWebKit

Alternatively, you probably want to extract the user agent string and group by that. To do that, you should use the built in extractions for iis or apache. If you are using apache, simply classify your sourcetype for these logs as access_combined.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...