Splunk Search

User agent Android 10 & IOS 14 - Difficult in extracting Field

advidlan
Loves-to-Learn

Hi 

I am trying to extract field from the user agent details like ( Operating system, Software, Software version, Software type, Os version, Hardware type) 

However i am finding some difficulty extracting the field . For example Operation system in Android, IOS & desktop are in the different field which highlighted below. 

Android user Mozilla/5.0 (LinuxAndroid 10SAMSUNG SM-T590AppleWebKit/537.36 (KHTMLlike GeckoSamsungBrowser / 12.1 Chrome/79.0.3945.136 Safari/537.36

 
 

Iphone user Mozilla/5.0 (iPhoneCPU iPhone OS 14_1 like Mac OS XAppleWebKit/605.1.15 (KHTMLlike GeckoVersion/14.0 Mobile/15E148 Safari/604.1

can someone help me how do extract field from the above user agent 

Software, Software version, Hardware type, Operation System,  Operating system name , Operation system version. 

Thanks 

View more huy dung service : thay pin iPhone 8 Plus - và dịch vụ ép kính iPhone lấy liền

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @advidlan,

the hints of @ITWhisperer guide you to the best approach to the problem.

This is a sample of this approach:

| rex "(Linux;|iPhone;\s+CPU\s+iPhone)\s+(?<os_versione>\w+\s+\w+)"

that you can test at https://regex101.com/r/km2EXB/1

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

User agent is not well defined - you could try looking at other posts on the subject, for example https://community.splunk.com/t5/Knowledge-Management/REX-command-issue-for-Multiple-user-agent/m-p/5...

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...