# Unnesting user\_agent fields

**URL:** <https://discuss.elastic.co/t/unnesting-user-agent-fields/173704>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 25, 2019, 9:29am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704 "2019-03-25T09:29:06Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![opfreehere](https://avatars.discourse-cdn.com/v4/letter/o/49beb7/32.png) [@opfreehere](https://discuss.elastic.co/u/opfreehere)\
**Post date:** [March 25, 2019, 9:29am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/1 "2019-03-25T09:29:06Z")

</div>

After using user\_agent processor, I am getting the results somewhat like this:  
"user\_agent" : {  
"patch" : "1",  
"major" : "5",  
"minor" : "1",  
"os" : "Android 5.1.1",  
"os\_minor" : "1",  
"os\_major" : "5",  
"name" : "Android",  
"os\_name" : "Android",  
"device" : "AFTT"  
}

I want the fields inside user\_agent to be split and parsed so that the JSON document looks like this  
"user\_agent" : {  
"patch" : "1",  
"major" : "5",  
"minor" : "1",  
"os" : "Android 5.1.1",  
"os\_minor" : "1",  
"os\_major" : "5",  
"name" : "Android",  
"os\_name" : "Android",  
"device" : "AFTT"  
},  
"patch" : "1",  
"major" : "5",  
"minor" : "1",  
"os" : "Android 5.1.1",  
"os\_minor" : "1",  
"os\_major" : "5",  
"name" : "Android",  
"os\_name" : "Android",  
"device" : "AFTT"

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 25, 2019, 10:05am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/2 "2019-03-25T10:05:49Z")

</div>

Do you mind pointing out what is the difference between the different versions you have pasted here?

---

<div class="post-metadata">

**Author:** ![opfreehere](https://avatars.discourse-cdn.com/v4/letter/o/49beb7/32.png) [@opfreehere](https://discuss.elastic.co/u/opfreehere)\
**Post date:** [March 25, 2019, 10:17am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/3 "2019-03-25T10:17:53Z")

</div>

I want to bring all the fields inside user\_agent field outside.

---

<div class="post-metadata">

**Author:** ![opfreehere](https://avatars.discourse-cdn.com/v4/letter/o/49beb7/32.png) [@opfreehere](https://discuss.elastic.co/u/opfreehere)\
**Post date:** [March 25, 2019, 10:19am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/4 "2019-03-25T10:19:46Z")

</div>

That is, rather than the field being user\_agent.os, I want it flattened. os. not nested.

---

<div class="post-metadata">

**Author:** ![BennyInc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bennyinc/32/21751_2.png) [@BennyInc](https://discuss.elastic.co/u/BennyInc)\
**Post date:** [March 25, 2019, 10:40am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/5 "2019-03-25T10:40:36Z")

</div>

Well, the user agent is dissected by the [User Agent processor](https://www.elastic.co/guide/en/elasticsearch/reference/master/user-agent-processor.html), which has a `target_field` option - the default being `"user-agent"`.  
I'm not sure whether you can configure it to use the root event? Maybe by specifying an empty `target_field`?

---

<div class="post-metadata">

**Author:** ![opfreehere](https://avatars.discourse-cdn.com/v4/letter/o/49beb7/32.png) [@opfreehere](https://discuss.elastic.co/u/opfreehere)\
**Post date:** [March 25, 2019, 10:43am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/6 "2019-03-25T10:43:50Z")

</div>

Did that, which lead to:

```
{
  "docs" : [
    {
      "error" : {
        "root_cause" : [
          {
            "type" : "exception",
            "reason" : "java.lang.IllegalArgumentException: java.lang.IllegalArgumentException: path cannot be null nor empty",
            "header" : {
              "processor_type" : "user_agent"
            }
          }
        ],
        "type" : "exception",
        "reason" : "java.lang.IllegalArgumentException: java.lang.IllegalArgumentException: path cannot be null nor empty",
        "caused_by" : {
          "type" : "illegal_argument_exception",
          "reason" : "java.lang.IllegalArgumentException: path cannot be null nor empty",
          "caused_by" : {
            "type" : "illegal_argument_exception",
            "reason" : "path cannot be null nor empty"
          }
        },
        "header" : {
          "processor_type" : "user_agent"
        }
      }
    }
  ]
}
```

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 25, 2019, 10:43am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/7 "2019-03-25T10:43:59Z")

</div>

Sorry, I misread the title of your post.  
Are you using any Filebeat modules? If not, this question should be moved to Elasticsearch subforum.

---

<div class="post-metadata">

**Author:** ![opfreehere](https://avatars.discourse-cdn.com/v4/letter/o/49beb7/32.png) [@opfreehere](https://discuss.elastic.co/u/opfreehere)\
**Post date:** [March 25, 2019, 10:44am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/8 "2019-03-25T10:44:27Z")

</div>

Yes, I am using Filebeat.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 25, 2019, 10:45am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/9 "2019-03-25T10:45:48Z")

</div>

I meant that if have enabled any module of Filebeat.

---

<div class="post-metadata">

**Author:** ![opfreehere](https://avatars.discourse-cdn.com/v4/letter/o/49beb7/32.png) [@opfreehere](https://discuss.elastic.co/u/opfreehere)\
**Post date:** [March 25, 2019, 10:47am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/10 "2019-03-25T10:47:12Z")

</div>

I am using ingest node to read log lines. Specifically, user agent processor.

---

<div class="post-metadata">

**Author:** ![opfreehere](https://avatars.discourse-cdn.com/v4/letter/o/49beb7/32.png) [@opfreehere](https://discuss.elastic.co/u/opfreehere)\
**Post date:** [March 25, 2019, 10:49am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/11 "2019-03-25T10:49:12Z")

</div>

I tried using rename processor and it creates large number of blocks. I am looking for some shorter way to move all those fields out of user\_agent field.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 25, 2019, 11:00am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/12 "2019-03-25T11:00:06Z")

</div>

In this case, you will have better luck posting your question in the Elasticsearch forum: [https://discuss.elastic.co/c/elasticsearch](https://discuss.elastic.co/c/elasticsearch) They develop Ingest node, so they will be able to help you. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 22, 2019, 11:00am UTC](https://discuss.elastic.co/t/unnesting-user-agent-fields/173704/13 "2019-04-22T11:00:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
