All Apps and Add-ons

How to update browsercaps file for TA-browscap?

jonhughes
Engager

I installed TA-browscap and have it working OK, but it seems that the browscap.csv file that the README says to download is a bit out of date - it doesn't seem to recognise IE 11 for example.

I tried downloading what I think is a newer version of the same format file (from browscap.org) but after restarting splunk, any search that I do involving the lookup fails with the error message Script for lookup table 'browscap_lookup' returned with error code 1. Results may be incorrect.

I tried to look into the source code to see if it was a simple problem to fix but I don't know python and I haven't been able to get anywhere.

Are there any simple edits I can make either to the Python source code or the csv file in order to make it work?

Tags (1)
1 Solution

dshpritz
SplunkTrust
SplunkTrust

Hey jonhughes,

It appears there was a change in the file format. The module I had been using needed, what turned out, to be a quick fix. I just uploaded v1.2 to Spunkbase, which may take a bit to populate. This version should work with the newer versions of the CSV files.

Thanks,

Dave

View solution in original post

cgbsplunk
Explorer

I tried updating browsecap file to csv file from browscap.org but I get the same error below. I can see the file format is different from the last one but in the TA-browscap ver 1.2 it says it was modified to accept the new format. Is there something else in settings I need to set so it knows it is the new format? I checked Splunk settings to make sure I am on ver 1.2 of TA-browscap.

Script for lookup table 'browscap_lookup' returned with error code 1. Results may be incorrect.

0 Karma

cluettr
Engager

got the same error. doesn't work for me.

robbie

dshpritz
SplunkTrust
SplunkTrust

Hey jonhughes,

It appears there was a change in the file format. The module I had been using needed, what turned out, to be a quick fix. I just uploaded v1.2 to Spunkbase, which may take a bit to populate. This version should work with the newer versions of the CSV files.

Thanks,

Dave

dshpritz
SplunkTrust
SplunkTrust

Please see: http://answers.splunk.com/answers/135078/browscap-ta-not-working-in-61/136751 There is a bug/feature in 6.1 that causes the default TA-browscap to break. I have a workaround, until Splunk replies to the ticket I have open to confirm.

0 Karma

anandhim
Path Finder

Hey Dave,

Any updates? We tried with 6.1.2 and it's not working.
Thanks

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Hey Bruce,

I haven't tested it with 6.1.1 yet. I'll give a shot and update when complete. It will hopefully be by the end of next week.

Dave

0 Karma

bruceclarke
Contributor

Hey Dave,

Do you have any update on getting browscap compatible with 6.1? Seems like it stopped working after the update. As a short term fix, we're using a macro to determine browser type, et al. Just curious if this is being looked into.

Thanks,
Bruce

0 Karma

GreyGryffin
New Member

I also note that there is a new download URL required.

See the release notes for TA_browscap (http://apps.splunk.com/app/1021/#) or visit http://browscap.org/ and reference the "Important Informaion" section. Old site URL is terminating 4/30/2014.

0 Karma

jonhughes
Engager

perfect, thanks!

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...