Not sure why -> everything looks installed correctly but I am not seeing the additional fields when running this search -> sourcetype = "iisw3c" | lookup browscap_lookup http_user_agent
We are running Splunk version 5.x -> could it be a version issue?
Two things to check:
Did you download the .csv file per the README at etc/apps/TA-browscap?
Assuming you did, the next question is does the http_user_agent field exist in event? if not, try running the search like this instead:
sourcetype="iisw3c" | eval http_user_agent=USERAGENT | lookup browscap_lookup http_user_agent
replacing USERAGENT with the correct field name containing the raw user agent string.
Two things to check:
Did you download the .csv file per the README at etc/apps/TA-browscap?
Assuming you did, the next question is does the http_user_agent field exist in event? if not, try running the search like this instead:
sourcetype="iisw3c" | eval http_user_agent=USERAGENT | lookup browscap_lookup http_user_agent
replacing USERAGENT with the correct field name containing the raw user agent string.
pmccomb, if this answer solved your problem, please mark it as 'accepted' by checking the checkbox. thanks!
Thank you. Check #2 did the trick. Thanks again for the help.
It could be a case sensitive issue. Lookups are case sensitive unless configured otherwise.