How bring the browser information using logstash

(Ganesh) #1

HI Team,
I have browser information in one field and how could i fetch browser version and name everything using logstash,

userAgent = Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.81 Safari/537.36

(Kilynn W) #2

(Ganesh) #3

without install this plugin i cannot perform the above action am i right

(Kilynn W) #4

Parse it yourself with dissect

(Ganesh) #5

while im trying to install ingest plugin in offline im getting below error,

./bin/elasticsearch-plugin install file:///usr/share/elasticsearch/
-> Downloading file:///usr/share/elasticsearch/
[=================================================] 100%??
ERROR: elasticsearch directory is missing in the plugin zip

(Kilynn W) #6

Path to your zip file is incorrect, make it simple and put the zip file in the /tmp directory
then use file:///tmp/


(Ganesh) #7


After solving that i'm getting below error

Exception in thread "main" /usr/tmp/elasticsearch/ (Not a directory)
        at Method)
        at org.elasticsearch.plugins.InstallPluginCommand.downloadZip(
        at org.elasticsearch.plugins.InstallPluginCommand.execute(
        at org.elasticsearch.plugins.InstallPluginCommand.execute(
        at org.elasticsearch.cli.EnvironmentAwareCommand.execute(
        at org.elasticsearch.cli.Command.mainWithoutErrorHandling(
        at org.elasticsearch.cli.MultiCommand.execute(
        at org.elasticsearch.cli.Command.mainWithoutErrorHandling(
        at org.elasticsearch.cli.Command.main(
        at org.elasticsearch.plugins.PluginCli.main(

(Magnus Bäck) #8

That's an ES plugin that the OP doesn't need. Use Logstash's useragent filter to parse useragent strings.

(Ganesh) #9

HI Magnusbaeck,
Initially i tried that way only but it doesnt work,

its contain the browser info "user_browserInfo"
useragent {

source =&gt; &quot;user_browserInfo&quot;

prefix =&gt; &quot;browserInfo_&quot;


am i doing any wrong

(Magnus Bäck) #10

Initially i tried that way only but it doesnt work,

What happens? What does an example event look like after processing (copy/paste raw JSON from Kibana)?

(Ganesh) #11

This is my json message,
`{"version":"1.0.0","environment":{"name":"1","hostName":"x","virtualMachine":"na","clusterName":"x","containerId":"na","containerName":"na","containerType":"JAVA"},"application":{"project":"na":"na","name":"na","type":"net"},"type":"REPORT","status":"Success","headers":{"httpStatusCode":200,"responseSize":0,"clientIp":"xx.x.x.x","referrerUrl":"na","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.81 Safari/537.36","saneId":"x.x.x.x","sessionToken":"na","publicGuid":"na","url":"na","requestMethod":"GET","locale":"na"},"responseTime":13,"timestamp":"2018-09-20T14:36:41.610Z","correlationId":"na","functionName":"/na","ervicesTimestamp":"2018-09-20T14:36:41.673Z"}

filter section,
json {
source => "message"
add_field => {
"user_browser" => "%{headers.userAgent}"
useragent {
source => "user_browser"
prefix => "browserInfo_"

(Ganesh) #12

Issue is fixed now and now i can extract the browser data.

(Kilynn W) #13

Thanks Magnus... my bad

(system) #14

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.