Splunk Search

Regex - Browser search

leberhart
New Member

I need to be able to find our users that are using the Safari browser. The user agent string looks something like this:

"Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.122 Safari/534.30"

I believe the regex string to be something like this: ^Mozilla/.*Safari.

So how to I properly form the search?

Side note: I have a whole set of regex to set the browser type based on the user agent string. Is this best accomplished with a lookup?

Tags (3)
0 Karma

Simeon
Splunk Employee
Splunk Employee

A search for all users of Safari should just be directed to your web access logs and the Safari or AppleWebKit keyword:

sourcetype=access_combined Safari AppleWebKit

Alternatively, you probably want to extract the user agent string and group by that. To do that, you should use the built in extractions for iis or apache. If you are using apache, simply classify your sourcetype for these logs as access_combined.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...