# Search on pipelines user-agent fields

**URL:** <https://discuss.elastic.co/t/search-on-pipelines-user-agent-fields/229516>\
**Category:** Elasticsearch\
**Created:** [April 23, 2020, 4:38pm UTC](https://discuss.elastic.co/t/search-on-pipelines-user-agent-fields/229516 "2020-04-23T16:38:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![the\_fire\_fades](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@the\_fire\_fades](https://discuss.elastic.co/u/the_fire_fades)\
**Post date:** [April 23, 2020, 4:38pm UTC](https://discuss.elastic.co/t/search-on-pipelines-user-agent-fields/229516/1 "2020-04-23T16:38:48Z")

</div>

Hello everybody,

I use the [https://www.elastic.co/guide/en/elasticsearch/reference/current/user-agent-processor.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/user-agent-processor.html) tutorial to extract the user-agent from a header that I put in my documents.

This works fine, I have exactly what I want when I see my document with for example that:  
GET customer/\_doc/9463  
I got:

```auto
    {
    	"customer_name": "doe",
    	"user_agent": {
    		"original": "Mozilla/5.0 (iPhone; CPU iPhone OS 13_1_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.1 Mobile/15E148 Safari/604.1",
    		"os": {
    			"name": "iOS",
    			"version": "13.1.2",
    			"full": "iOS 13.1.2"
    		},
    		"name": "Mobile Safari",
    		"device": {
    			"name": "iPhone"
    		},
    		"version": "13.0.1"
    	},
    	"city": paris
    }

```

But when I try to do an aggregation on user\_agent or just query match nothing happens... It's like my field is only for view purpose but not to search on it. I think that extra fieds that have been generated by pipeline are accessible by another way that the tradiotional:

```auto
{
"query": {"match":{"my_field":"my_value"}}
}

```

But how. I'm relatively so any advice gonna be a great help. Thanks

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 24, 2020, 2:47am UTC](https://discuss.elastic.co/t/search-on-pipelines-user-agent-fields/229516/2 "2020-04-24T02:47:45Z")

</div>

Welcome!

Check the mapping for this field. It must be using a `keyword` datatype.  
If you are using the default mapping, there's probably a subfield `keyword` like `user_agent.name.keyword` which you can use for aggs.

---

<div class="post-metadata">

**Author:** ![the\_fire\_fades](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@the\_fire\_fades](https://discuss.elastic.co/u/the_fire_fades)\
**Post date:** [April 24, 2020, 10:43am UTC](https://discuss.elastic.co/t/search-on-pipelines-user-agent-fields/229516/3 "2020-04-24T10:43:50Z")

</div>

Thanks for the response,

Acutally it's really weird because if I type:

`GET customer/_mapping/field/user_agent`

I got

```
{
  "seed": {
    "mappings": {}
  }
}

```

But what is really weird that I see my value when I do  
`GET seed/_doc/28`  
I got

```
{

```

(...)  
"user\_agent": {  
"original": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36",  
"os": {  
"name": "Windows 10"  
},  
"name": "Chrome",  
"device": {  
"name": "Other"  
},  
"version": "78.0.3904"  
},  
(...)  
}  
It's like my document has the user\_agent field but not user\_agent is not mapped.  
What I uderstand of pipleine is that a pipeline "transform" a document and add some extra fields, before the indexation. The pipeline add the extra fields with the mapping so why I can find my user\_agent field with _GET seed/\_doc/28_ but not in mapping ?

To be more specific about this issue, the indaxation is made in php by the bundle elastica. Maybe the problem is due to that 🤔

---

<div class="post-metadata">

**Author:** ![the\_fire\_fades](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@the\_fire\_fades](https://discuss.elastic.co/u/the_fire_fades)\
**Post date:** [April 24, 2020, 10:52am UTC](https://discuss.elastic.co/t/search-on-pipelines-user-agent-fields/229516/4 "2020-04-24T10:52:30Z")

</div>

I find why !

In my mapping I had  
{  
"seed": {  
"mappings": {  
"dynamic": "false",  
"properties": {

So my mapping was never made for user\_agent field. I remove the dynamic configuration and now by default may mapping is made so I (finally) found my mapping for user\_agent.

Thanks again for the response.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2020, 10:52am UTC](https://discuss.elastic.co/t/search-on-pipelines-user-agent-fields/229516/5 "2020-05-22T10:52:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
