# Invalid User Agent String

**URL:** <https://discuss.elastic.co/t/invalid-user-agent-string/181048>\
**Category:** APM\
**Tags:** rum, server\
**Created:** [May 14, 2019, 5:15pm UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048 "2019-05-14T17:15:50Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![anushshukla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushshukla/32/46173_2.png) [@anushshukla](https://discuss.elastic.co/u/anushshukla)\
**Post date:** [May 14, 2019, 5:15pm UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/1 "2019-05-14T17:15:51Z")

</div>

We have observed that the user agent string (user\_agent.original field name) in kibana logs is showing as

> fp/f99c5a

for all or any web view browsers instead of the actual user agent string.

To verify and confirm it, we have started sending the user agent string in tags of the APM transactional RUM events at client side to verify the same which we did (please refer the below screenshot).

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/1/21df7b3e41879367a97526dae7d16f5acdec155d.png)

Please help us in resolving this issue which we are facing!

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [May 14, 2019, 6:53pm UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/2 "2019-05-14T18:53:38Z")

</div>

Can you confirm this data is coming from the an APM agent, if so, which one?

---

<div class="post-metadata">

**Author:** ![anushshukla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushshukla/32/46173_2.png) [@anushshukla](https://discuss.elastic.co/u/anushshukla)\
**Post date:** [May 16, 2019, 5:39am UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/3 "2019-05-16T05:39:31Z")

</div>

@tylersmalley, Yes it is coming from APM agent after we added the below configuration

`apm-server.register.ingest.pipeline.enabled: true  
output.elasticsearch.pipelines:

- pipeline: "apm\_user\_agent"`

to **apm-server.yml**.

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [May 16, 2019, 3:38pm UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/4 "2019-05-16T15:38:23Z")

</div>

I am going to move this to the APM group, someone there should be able to provide some more help

---

<div class="post-metadata">

**Author:** ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)\
**Post date:** [May 21, 2019, 9:52am UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/5 "2019-05-21T09:52:55Z")

</div>

This indeed looks suspicious. There are currently two ways how the APM Server enriches data with the UserAgent information: It either parses the information directly from the `User-Agent` header from the agent request, or in case the ndjson body sent by the agent includes a `User-Agent` in the `context.request.headers`, this information is set as `user_agent.original`.

You mention you added the `UserAgent` as label. Where did you parse the information from, is it sent as headers with the agent request?

---

<div class="post-metadata">

**Author:** ![anushshukla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushshukla/32/46173_2.png) [@anushshukla](https://discuss.elastic.co/u/anushshukla)\
**Post date:** [May 21, 2019, 11:55am UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/6 "2019-05-21T11:55:01Z")

</div>

@simitt thank you for looking into this. With reference to the screenshot above in the question, the labels.userAgent value is being sent from the browser's user agent from the client side by adding it in the tags during the APM RUM transaction events. Let me know if more information is required from my side.

---

<div class="post-metadata">

**Author:** ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)\
**Post date:** [May 22, 2019, 1:09pm UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/7 "2019-05-22T13:09:40Z")

</div>

The APM Server doesn't process this information from `labels`, but either from the `headers` that are sent by the agent, or from whatever is sent within `context.request.headers` under `user-agent`. You should be able to find the headers in your APM Server logs. Can you confirm that the user agent information there is the same as the one you are sending in the `labels`?

Which versions of Elasticsearch, APM Server and the RUM agent are you running?

---

<div class="post-metadata">

**Author:** ![anushshukla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushshukla/32/46173_2.png) [@anushshukla](https://discuss.elastic.co/u/anushshukla)\
**Post date:** [May 24, 2019, 5:14am UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/8 "2019-05-24T05:14:47Z")

</div>

With references to below screenshot, the APM server responds with `fp/f99c5a` in it's header of server key name while in the request header of User-Agent the value is correct. I am just sending the actual user agent string (same as User-Agent request header) in tags for other purposes because due to APM server or Kibana logs, the user\_agent.original field name is incorrect.

 ![Screenshot%20from%202019-05-24%2010-36-45](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cdaf60413c75b989f8f0a8369fef8692b282906b.png)

Please note that we are using `https://unpkg.com/@elastic/apm-rum@4.0.1/dist/bundles/elastic-apm-rum.umd.min.js` script inclusion in out frontend application which is built on React JavaScript framework.

---

<div class="post-metadata">

**Author:** ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)\
**Post date:** [May 28, 2019, 6:38am UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/9 "2019-05-28T06:38:15Z")

</div>

Unfortunately I cannot reproduce this behavior locally, sending requests with some of the `user-agent` info showed in your examples, results in properly set `user_agent` information in Elasticsearch.

Do you have anything additionally set up, any proxies in between or any non-default configurations that could give a hint? And can you share which versions of the agent, APM Server and Elasticsearch you are using?

---

<div class="post-metadata">

**Author:** ![anushshukla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushshukla/32/46173_2.png) [@anushshukla](https://discuss.elastic.co/u/anushshukla)\
**Post date:** [June 1, 2019, 4:33pm UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/10 "2019-06-01T16:33:38Z")

</div>

No proxy setup.

v7.1.1 is the deployment version.

The only configuration change is at in User Settings Overrides (apm-server.yml) of APM server which is

```
apm-server.register.ingest.pipeline.enabled: true
output.elasticsearch.pipelines:
 - pipeline: "apm_user_agent"
```

---

<div class="post-metadata">

**Author:** ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)\
**Post date:** [June 3, 2019, 11:02am UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/11 "2019-06-03T11:02:42Z")

</div>

The issue appears when the `user-agent` string contains `[]` chars. I have forwarded the issue internally and will keep you updated.

---

<div class="post-metadata">

**Author:** ![anushshukla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushshukla/32/46173_2.png) [@anushshukla](https://discuss.elastic.co/u/anushshukla)\
**Post date:** [June 3, 2019, 12:07pm UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/12 "2019-06-03T12:07:33Z")

</div>

Thank you, @simitt for your continuous support.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 1, 2019, 12:14pm UTC](https://discuss.elastic.co/t/invalid-user-agent-string/181048/13 "2019-07-01T12:14:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
