Can someone please help me extract all different OS types from my logs. is there anyway Single rex query i can write to extract all possible OStypes
I see - Windows NT, MAC OS, Linux Android 6.0, Linux Android 7.0, ,there are few more
See sample logs
"Login","XXXX","XXXXX","XXXX","XXXXX","435","66","XXXXX","/index.jsp","","","","XXXX","XXXX","Mozilla/5.0 (Linux; Android 6.0.1; SM-G900V Build/MMB29M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/XXXXX Mobile Safari/XXX","","9998.0","","XXXX","XXXXX","2016-11-17T23:59:CSCS","XXXXX",""
--
"Login","XCCXC","XXXX-XXXX-","XXX","XXX","155","12","XXXX","/services/oauth2/token","","","","XXXX","XXXX","SalesforceMobileSDK/3.1.0 android mobile/6.0.1 (SM-G900V) Salesforce1/XXX Native","","XXXXX","","XCXc","XXX-XXX-XXX-GCM-XXX","2016-11-17ScT23:59:SCSCSc","XXX",""
----
Hi splgeek
The following search code give you : Linux; Android 6.0.1;
index="your index_name"|rex field=_raw "(?<myfield>[\w+\;\s+\w+\s+\.\d+]+\;)"|table myfield
thanks
so thats just for extracting linux?
is there anyway to extract them all with 1 query?
Please can you extend your sample logs , for permitting me to see well your events ?
i need to see well before extracting
This answer may help.
as a refresher could you /anyone give me the spl query with rex/regex to extract these OS types with a field label name as Ostype
I cannot install any TA's for this