# Urldecode useragent cloudfront

**URL:** https://discuss.elastic.co/t/urldecode-useragent-cloudfront/110200
**Category:** Logstash
**Created:** [December 4, 2017, 6:47pm UTC](https://discuss.elastic.co/t/urldecode-useragent-cloudfront/110200 "2017-12-04T18:47:28Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![qmaerik](https://avatars.discourse-cdn.com/v4/letter/q/cab0a1/32.png) [@qmaerik](https://discuss.elastic.co/u/qmaerik)
#### Post date: [December 4, 2017, 6:47pm UTC](https://discuss.elastic.co/t/urldecode-useragent-cloudfront/110200/1 "2017-12-04T18:47:28Z")

</div>

I' m having problems with the urldecode filter and can't get it to work on any field so far and I can't figure out what I am doing wrong.

I have a grok filter that is parsing the agent field just fine, but when adding urldecode { field =\> "agent" } the data sent to ES is still url encoded.

```
input {
    s3 {
            bucket => "mybucket"
            delete => false
            interval => 60 # seconds
            prefix => "cf-logs/"
            region => "myregion"
            type => "cloudfront"
            codec => "plain"
    }
}
filter {
    if [type] == "cloudfront" {
            if ( ("#Version: 1.0" in [message]) or ("#Fields: date" in [message])) {
                    drop {}
            }
            grok {
                    tag_on_failure => "message-err"
                    match => { "message" => "%{DATE_EU:date}\t%{TIME:time}\t%{DATA:x_edge_location}\t(?:%{NUMBER:bytes}|-)\t%{IPORHOST:clientip}\t%{WORD:verb}\t%{HOSTNAME:cs_host}\t%{NOTSPACE:request}\t%{NUMBER:response}\t(?:%{NOTSPACE:referrer}|-)\t(?:%{GREEDYDATA:agent}|-)\t(?:%{GREEDYDATA:cs_uri_stem}|-)\t%{GREEDYDATA:cookies}\t%{WORD:x_edge_result_type}\t%{NOTSPACE:x_edge_request_id}\t%{HOSTNAME:x_host_header}\t%{URIPROTO:protocol}\t%{INT:bytes}\t%{NUMBER:responsetime:float}\t(?:%{NOTSPACE:x_forwarded_for}|)\t%{GREEDYDATA:ssl_protocol}\t%{GREEDYDATA:ssl_cipher}\t%{GREEDYDATA:x_edge_response_result_type}\t%{GREEDYDATA:httpversion}" }
            }
            urldecode { field => "agent" }
    }
}
output {
    elasticsearch {
            hosts => ["ES:80"]
            }
}

```

Still the data send to ES is url endocded e.g:  
Mozilla/5.0%20(Windows%20NT%206.1;%20Win64;%20x64)%20AppleWebKit/537.36%20(KHTML,%20like%20Gecko)%20Chrome/62.0.3202.94%20Safari/537.36

---

<div class="post-metadata">

### Author: ![qmaerik](https://avatars.discourse-cdn.com/v4/letter/q/cab0a1/32.png) [@qmaerik](https://discuss.elastic.co/u/qmaerik)
#### Post date: [December 5, 2017, 2:02pm UTC](https://discuss.elastic.co/t/urldecode-useragent-cloudfront/110200/2 "2017-12-05T14:02:59Z")

</div>

Just needed to run it twice on agent field. Missed it was %2520 and it could not be handled in one run of urldecode filter

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 2, 2018, 2:03pm UTC](https://discuss.elastic.co/t/urldecode-useragent-cloudfront/110200/3 "2018-01-02T14:03:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
