Hi,
We use a 3rd party python library (ua_parser) that does a great job of parsing the myriad useragents that hit our site.
Is it possible to call such a library at either index or search time?
Obviously performance might be an issue, but I wanted to at least see if it was possible.
thanks.
Jon.
Index-time, no. Luckily, as it would have horrible performane implications 😉
Search-time, certainly. Set up a script that serves as a dynamic lookup. More information in the docs here: http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources#Set_up...