# Fingerprint to get the last out of user\_agent

**URL:** <https://discuss.elastic.co/t/fingerprint-to-get-the-last-out-of-user-agent/229120>\
**Category:** Logstash\
**Created:** [April 21, 2020, 6:39pm UTC](https://discuss.elastic.co/t/fingerprint-to-get-the-last-out-of-user-agent/229120 "2020-04-21T18:39:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [April 21, 2020, 6:39pm UTC](https://discuss.elastic.co/t/fingerprint-to-get-the-last-out-of-user-agent/229120/1 "2020-04-21T18:39:45Z")

</div>

Hi i have now nearly finished the parsing of my nginx access logfile.

This line is the "user\_agent" field. I parse with my filter already different stuff out of that.

Chrome example:

> "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.163 Safari/537.36"

Android example:

> "Mozilla/5.0 (Linux; Android 10; Pixel 3)

I want to use fingerprint or something to get the version (Android 10 or 10.0) and if possible I want to have in seperate field "Pixel" or "Win64".

Filters:

> if [event][module] == "nginx" {  
> if [fileset][name] == "access" {  
> mutate {  
> add\_tag =\> ["anginx", "Anginx"]  
> }  
> if "anginx" in [tags] {  
> grok {  
> match =\> { "message" =\> "%{HTTPD\_COMMONLOG} %{QS:referrer} %{QS:user\_agent}" }  
> # remove\_field =\> "message"  
> }  
> mutate {  
> gsub =\> ["referrer", '^"', '', "referrer", '"$', '']  
> }  
> mutate {  
> gsub =\> ["user\_agent", '^"', '', "user\_agent", '"$', '']  
> }  
> mutate {  
> add\_field =\> { "read\_timestamp" =\> "%{@timestamp}" }  
> }  
> date {  
> match =\> ["[nginx][access][time]", "dd/MMM/YYYY:H:m:s Z" ]  
> remove\_field =\> "[nginx][access][time]"  
> }  
> useragent {  
> source =\> "[user\_agent]"  
> target =\> "[ua\_parsed]"  
> add\_tag =\> ["ua\_parsed"]  
> # remove\_field =\> "[nginx][access][user\_agent]"  
> }  
> if ([user\_agent]) {  
> mutate { add\_field =\> { "[http][product]" =\> "%{[user\_agent]}" } }  
> mutate { gsub =\> ["[http][product]", "(._)", " "] }  
> mutate { add\_field =\> { "[http][product\_version]" =\> "%{[http][product]}" } }  
> mutate { split =\> ["[http][product]", " " ] }  
> mutate { gsub =\> ["[http][product]", "/._", ""] }  
> mutate { split =\> ["[http][product\_version]", " " ] }  
> }

Pase of a whole Json parsed from Kibana:

[https://pastebin.com/M3J8p76S](https://pastebin.com/M3J8p76S)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2020, 6:48pm UTC](https://discuss.elastic.co/t/fingerprint-to-get-the-last-out-of-user-agent/229120/2 "2020-05-19T18:48:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
