All Apps and Add-ons

How to update browsercaps file for TA-browscap?

jonhughes
Engager

I installed TA-browscap and have it working OK, but it seems that the browscap.csv file that the README says to download is a bit out of date - it doesn't seem to recognise IE 11 for example.

I tried downloading what I think is a newer version of the same format file (from browscap.org) but after restarting splunk, any search that I do involving the lookup fails with the error message Script for lookup table 'browscap_lookup' returned with error code 1. Results may be incorrect.

I tried to look into the source code to see if it was a simple problem to fix but I don't know python and I haven't been able to get anywhere.

Are there any simple edits I can make either to the Python source code or the csv file in order to make it work?

Tags (1)
1 Solution

dshpritz
SplunkTrust
SplunkTrust

Hey jonhughes,

It appears there was a change in the file format. The module I had been using needed, what turned out, to be a quick fix. I just uploaded v1.2 to Spunkbase, which may take a bit to populate. This version should work with the newer versions of the CSV files.

Thanks,

Dave

View solution in original post

cgbsplunk
Explorer

I tried updating browsecap file to csv file from browscap.org but I get the same error below. I can see the file format is different from the last one but in the TA-browscap ver 1.2 it says it was modified to accept the new format. Is there something else in settings I need to set so it knows it is the new format? I checked Splunk settings to make sure I am on ver 1.2 of TA-browscap.

Script for lookup table 'browscap_lookup' returned with error code 1. Results may be incorrect.

0 Karma

cluettr
Engager

got the same error. doesn't work for me.

robbie

dshpritz
SplunkTrust
SplunkTrust

Hey jonhughes,

It appears there was a change in the file format. The module I had been using needed, what turned out, to be a quick fix. I just uploaded v1.2 to Spunkbase, which may take a bit to populate. This version should work with the newer versions of the CSV files.

Thanks,

Dave

dshpritz
SplunkTrust
SplunkTrust

Please see: http://answers.splunk.com/answers/135078/browscap-ta-not-working-in-61/136751 There is a bug/feature in 6.1 that causes the default TA-browscap to break. I have a workaround, until Splunk replies to the ticket I have open to confirm.

0 Karma

anandhim
Path Finder

Hey Dave,

Any updates? We tried with 6.1.2 and it's not working.
Thanks

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Hey Bruce,

I haven't tested it with 6.1.1 yet. I'll give a shot and update when complete. It will hopefully be by the end of next week.

Dave

0 Karma

bruceclarke
Contributor

Hey Dave,

Do you have any update on getting browscap compatible with 6.1? Seems like it stopped working after the update. As a short term fix, we're using a macro to determine browser type, et al. Just curious if this is being looked into.

Thanks,
Bruce

0 Karma

GreyGryffin
New Member

I also note that there is a new download URL required.

See the release notes for TA_browscap (http://apps.splunk.com/app/1021/#) or visit http://browscap.org/ and reference the "Important Informaion" section. Old site URL is terminating 4/30/2014.

0 Karma

jonhughes
Engager

perfect, thanks!

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...