All Apps and Add-ons

Manually input lookup data on server?

dewald13
Path Finder

Is there any way to manually input the library to do the lookup command? The network that I am trying to do this on is locked down and my Splunk server cannot hit the website to update the cache.

Any help will be greatly appreciated!

Tags (2)
0 Karma

dshpritz
SplunkTrust
SplunkTrust

This may not be just you. It looks like the user-agent-string.info site is down, which may be causing your problem.

As an alternative, I also have TA-browscap which has similar capabilities, but was more geared towards web analytics. It can be found here:

TA-browscap

It does allow (actually require) that you manually download the data file.

Thanks,

Dave

0 Karma

dshpritz
SplunkTrust
SplunkTrust

I'm afraid not. After the update script downloads the file from the user-agent-string.info site, it uses the pickle module to parse and the serialize the data to the cache file. Can you contact me (there is a contact link on the TA-uas_parser page) so I can get a better idea of your requirements?

Thanks,

Dave

0 Karma

dewald13
Path Finder

I dont even think we will be able to do that. Is there anywhere you know of the site I can download it from directly?

0 Karma

dshpritz
SplunkTrust
SplunkTrust

If you have a system which is not on a locked down network, you can run the "update_cache.py" script to download the data file. It will run the processing needed to create the cache file in the /bin/ua_cache/ directory. You can then copy the /bin/ua_cache/cache file to the locked down server for use. Let me know if that solution works for you.

Dave

0 Karma

dewald13
Path Finder

We are aware the site is having some issues but either way, we cannot get out of our network and hit it to download what is needed. Is there a way to accomplish this manually??

We have also looked at your TA-browscap app but that is not what we are looking for. We need to break down our user agent strings.

Please advise if there is a workaround.

thanks,
doug

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...