# How bring the browser information using logstash

**URL:** <https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113>\
**Category:** Logstash\
**Created:** [September 19, 2018, 11:11am UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113 "2018-09-19T11:11:08Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [September 19, 2018, 11:11am UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/1 "2018-09-19T11:11:08Z")

</div>

HI Team,  
I have browser information in one field and how could i fetch browser version and name everything using logstash,

userAgent = Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.81 Safari/537.36

---

<div class="post-metadata">

**Author:** ![sm00thindian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sm00thindian/32/27376_2.png) [@sm00thindian](https://discuss.elastic.co/u/sm00thindian)\
**Post date:** [September 19, 2018, 1:44pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/2 "2018-09-19T13:44:31Z")

</div>

[https://www.elastic.co/guide/en/elasticsearch/plugins/6.4/ingest-user-agent.html](https://www.elastic.co/guide/en/elasticsearch/plugins/6.4/ingest-user-agent.html)

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [September 19, 2018, 1:57pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/3 "2018-09-19T13:57:56Z")

</div>

without install this plugin i cannot perform the above action am i right

---

<div class="post-metadata">

**Author:** ![sm00thindian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sm00thindian/32/27376_2.png) [@sm00thindian](https://discuss.elastic.co/u/sm00thindian)\
**Post date:** [September 19, 2018, 2:10pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/4 "2018-09-19T14:10:12Z")

</div>

Parse it yourself with dissect  
[https://www.elastic.co/guide/en/logstash/6.4/field-extraction.html](https://www.elastic.co/guide/en/logstash/6.4/field-extraction.html)

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [September 19, 2018, 2:30pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/5 "2018-09-19T14:30:02Z")

</div>

while im trying to install ingest plugin in offline im getting below error,

./bin/elasticsearch-plugin install file:///usr/share/elasticsearch/ingest-user-agent-6.4.0.zip  
-\> Downloading file:///usr/share/elasticsearch/ingest-user-agent-6.4.0.zip  
[=================================================] 100%??  
ERROR: `elasticsearch` directory is missing in the plugin zip

---

<div class="post-metadata">

**Author:** ![sm00thindian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sm00thindian/32/27376_2.png) [@sm00thindian](https://discuss.elastic.co/u/sm00thindian)\
**Post date:** [September 19, 2018, 2:35pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/6 "2018-09-19T14:35:20Z")

</div>

Path to your zip file is incorrect, make it simple and put the zip file in the /tmp directory  
then use file:///tmp/ingest-user-agent-6.4.0.zip

-krw

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [September 19, 2018, 2:38pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/7 "2018-09-19T14:38:36Z")

</div>

Thanks,

After solving that i'm getting below error

```
Exception in thread "main" java.io.FileNotFoundException: /usr/tmp/elasticsearch/ingest-user-agent-6.4.0.zip (Not a directory)
        at java.io.FileInputStream.open0(Native Method)
        at java.io.FileInputStream.open(FileInputStream.java:195)
        at java.io.FileInputStream.<init>(FileInputStream.java:138)
        at java.io.FileInputStream.<init>(FileInputStream.java:93)
        at sun.net.www.protocol.file.FileURLConnection.connect(FileURLConnection.java:90)
        at sun.net.www.protocol.file.FileURLConnection.getInputStream(FileURLConnection.java:188)
        at org.elasticsearch.plugins.InstallPluginCommand.downloadZip(InstallPluginCommand.java:334)
        at org.elasticsearch.plugins.InstallPluginCommand.download(InstallPluginCommand.java:253)
        at org.elasticsearch.plugins.InstallPluginCommand.execute(InstallPluginCommand.java:221)
        at org.elasticsearch.plugins.InstallPluginCommand.execute(InstallPluginCommand.java:212)
        at org.elasticsearch.cli.EnvironmentAwareCommand.execute(EnvironmentAwareCommand.java:86)
        at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:124)
        at org.elasticsearch.cli.MultiCommand.execute(MultiCommand.java:75)
        at org.elasticsearch.cli.Command.mainWithoutErrorHandling(Command.java:124)
        at org.elasticsearch.cli.Command.main(Command.java:90)
        at org.elasticsearch.plugins.PluginCli.main(PluginCli.java:48)
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 20, 2018, 1:26pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/8 "2018-09-20T13:26:50Z")

</div>

> [https://www.elastic.co/guide/en/elasticsearch/plugins/6.4/ingest-user-agent.html](https://www.elastic.co/guide/en/elasticsearch/plugins/6.4/ingest-user-agent.html)

That's an ES plugin that the OP doesn't need. Use Logstash's useragent filter to parse useragent strings.

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [September 20, 2018, 1:43pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/9 "2018-09-20T13:43:11Z")

</div>

HI Magnusbaeck,  
Initially i tried that way only but it doesnt work,

its contain the browser info "user\_browserInfo"  
useragent {

```
source =&gt; &quot;user_browserInfo&quot;

prefix =&gt; &quot;browserInfo_&quot;

}

```

am i doing any wrong

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 20, 2018, 2:46pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/10 "2018-09-20T14:46:49Z")

</div>

> Initially i tried that way only but it doesnt work,

What happens? What does an example event look like after processing (copy/paste raw JSON from Kibana)?

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [September 20, 2018, 2:51pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/11 "2018-09-20T14:51:21Z")

</div>

> [@magnusbaeck](#):
>
> That's an ES plugin that the OP doesn't need. Use Logstash's useragent filter to parse useragent strings.

HI,  
This is my json message,  
`{"version":"1.0.0","environment":{"name":"1","hostName":"x","virtualMachine":"na","clusterName":"x","containerId":"na","containerName":"na","containerType":"JAVA"},"application":{"project":"na":"na","name":"na","type":"net"},"type":"REPORT","status":"Success","headers":{"httpStatusCode":200,"responseSize":0,"clientIp":"xx.x.x.x","referrerUrl":"na","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.81 Safari/537.36","saneId":"x.x.x.x","sessionToken":"na","publicGuid":"na","url":"na","requestMethod":"GET","locale":"na"},"responseTime":13,"timestamp":"2018-09-20T14:36:41.610Z","correlationId":"na","functionName":"/na","ervicesTimestamp":"2018-09-20T14:36:41.673Z"}

filter section,  
json {  
source =\> "message"  
}  
mutate{  
add\_field =\> {  
"user\_browser" =\> "%{headers.userAgent}"  
}  
}  
useragent {  
source =\> "user\_browser"  
prefix =\> "browserInfo\_"  
}

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [September 20, 2018, 2:57pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/12 "2018-09-20T14:57:56Z")

</div>

Issue is fixed now and now i can extract the browser data.

---

<div class="post-metadata">

**Author:** ![sm00thindian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sm00thindian/32/27376_2.png) [@sm00thindian](https://discuss.elastic.co/u/sm00thindian)\
**Post date:** [September 27, 2018, 3:15pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/13 "2018-09-27T15:15:37Z")

</div>

Thanks Magnus... my bad

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2018, 3:15pm UTC](https://discuss.elastic.co/t/how-bring-the-browser-information-using-logstash/149113/14 "2018-10-25T15:15:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
