# Logstash grok pattern COMBINEDAPACHELOG field name collision with latest filebeat 7.2.0 client and logstash useragent plugin

**URL:** <https://discuss.elastic.co/t/logstash-grok-pattern-combinedapachelog-field-name-collision-with-latest-filebeat-7-2-0-client-and-logstash-useragent-plugin/191584>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 22, 2019, 6:41am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-combinedapachelog-field-name-collision-with-latest-filebeat-7-2-0-client-and-logstash-useragent-plugin/191584 "2019-07-22T06:41:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![iuuuuan](https://avatars.discourse-cdn.com/v4/letter/i/a9a28c/32.png) [@iuuuuan](https://discuss.elastic.co/u/iuuuuan)\
**Post date:** [July 22, 2019, 6:41am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-combinedapachelog-field-name-collision-with-latest-filebeat-7-2-0-client-and-logstash-useragent-plugin/191584/1 "2019-07-22T06:41:43Z")

</div>

Hi,

there seems to be issues with logstash grok pattern COMBINEDAPACHELOG with latest filebeat 7.2.0 client and logstash useragent plugin.

I am using grok pattern COMBINEDAPACHELOG which translates to %{COMMONAPACHELOG} %{QS:referrer} %{QS:agent}.

Latest filebeat client is sending agent field with following properties:  
agent.ephemeral\_id  
agent.hostname  
agent.id  
agent.type  
agent.version

I am using logstash-filter-useragent with following configuration:

if ([agent]) {  
useragent {  
source =\> "agent"  
target =\> "user\_agent"  
remove\_field =\> "agent"  
}  
}

Filebeat clients overwrites agent field from grok pattern COMBINEDAPACHELOG with filebeat agent field which results with errors in logstash:

[ERROR][logstash.filters.useragent] Uknown error while parsing user agent data {:exception=\>#\<TypeError: cannot convert instance of class org.jruby.RubyHash to class java.lang.String\>, :field=\>"agent", :event=\>#LogStash::Event:0x6b358a65}

One solution of the problem would be changing COMBINEDAPACHELOG grok pattern to COMMONAPACHELOG %{QS:referrer} %{QS:someotherfield} and modify useragent configuration.

Is there any configuration option on filebeat client - change field agent to something else ?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [July 25, 2019, 6:33pm UTC](https://discuss.elastic.co/t/logstash-grok-pattern-combinedapachelog-field-name-collision-with-latest-filebeat-7-2-0-client-and-logstash-useragent-plugin/191584/2 "2019-07-25T18:33:13Z")

</div>

Hello @iuuuuan,

The grok pattern that you are referring is located in Logstash? You could use the mutate the event before applying the grok?

---

<div class="post-metadata">

**Author:** ![iuuuuan](https://avatars.discourse-cdn.com/v4/letter/i/a9a28c/32.png) [@iuuuuan](https://discuss.elastic.co/u/iuuuuan)\
**Post date:** [July 26, 2019, 6:25am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-combinedapachelog-field-name-collision-with-latest-filebeat-7-2-0-client-and-logstash-useragent-plugin/191584/3 "2019-07-26T06:25:42Z")

</div>

Yes it is located in Logstash.

I have changed COMBINEDAPACHELOG to COMMONAPACHELOG %{QS:referrer} %{QS:browser} and modified useragent section to:

if ([browser]) {  
useragent {  
source =\> "browser"  
target =\> "user\_agent"  
remove\_field =\> "browser"  
}  
}

This configuration is working.

Base logstash grok patterns are described on [https://github.com/elastic/logstash/blob/v1.4.2/patterns/grok-patterns](https://github.com/elastic/logstash/blob/v1.4.2/patterns/grok-patterns).

Ok I could also use mutate with rename

mutate {  
rename =\> ["agent", "filebeat\_agent"]  
}

But the basic problem still persists - filebeat agent creates field with name agent and grok pattern COMBINEDAPACHELOG has same field name as filebeat agent.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [July 26, 2019, 12:52pm UTC](https://discuss.elastic.co/t/logstash-grok-pattern-combinedapachelog-field-name-collision-with-latest-filebeat-7-2-0-client-and-logstash-useragent-plugin/191584/4 "2019-07-26T12:52:48Z")

</div>

I understand the conflict, glad there is a workaround the problem. But I agree we could make a bit of work to make sure that fields extracted from grok pattern doesn't do any conflict with fields defined by filebeat.

I suggest you to create an issue on the logstash pattern repository [https://github.com/logstash-plugins/logstash-patterns-core](https://github.com/logstash-plugins/logstash-patterns-core)

But keep in mind I am not sure that we can solve all theses conflict.

---

<div class="post-metadata">

**Author:** ![iuuuuan](https://avatars.discourse-cdn.com/v4/letter/i/a9a28c/32.png) [@iuuuuan](https://discuss.elastic.co/u/iuuuuan)\
**Post date:** [July 29, 2019, 8:53am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-combinedapachelog-field-name-collision-with-latest-filebeat-7-2-0-client-and-logstash-useragent-plugin/191584/5 "2019-07-29T08:53:34Z")

</div>

What if I create issue for filebeat instead ? Grok pattern COMBINEDAPACHELOG is used for a long time now, filebeat agent field feature has been added recently ? Or maybe feature request for filebeat - add configuration option for filebeat field name. According to [https://github.com/elastic/beats/blob/master/CHANGELOG.asciidoc](https://github.com/elastic/beats/blob/master/CHANGELOG.asciidoc) agent field name has been changed from beat.name to agent.type, beat.hostname to agent.hostname and beat.version to agent.version version 7.0.0-alpha1.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 26, 2019, 8:53am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-combinedapachelog-field-name-collision-with-latest-filebeat-7-2-0-client-and-logstash-useragent-plugin/191584/6 "2019-08-26T08:53:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
