# User Agent Raw Mapping

**URL:** <https://discuss.elastic.co/t/user-agent-raw-mapping/59533>\
**Category:** Logstash\
**Created:** [September 1, 2016, 10:29am UTC](https://discuss.elastic.co/t/user-agent-raw-mapping/59533 "2016-09-01T10:29:46Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![JoeeGrigg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joeegrigg/32/4411_2.png) [@JoeeGrigg](https://discuss.elastic.co/u/JoeeGrigg)\
**Post date:** [September 1, 2016, 10:29am UTC](https://discuss.elastic.co/t/user-agent-raw-mapping/59533/1 "2016-09-01T10:29:46Z")

</div>

HI,

I have recently set up Elasticsearch, Logstash and Kibana.

My Logstash includes the useragent plugin and all that seems to be working fine.

My problem is when it comes to visualising the user agent the separate words in the os\_name field are been split into separate sections on the chart. I am pretty sure that this is being caused by elasticsearch using each of the words as separate tokens but I am lost when it comes to making them be read as one token.

Can anyone help?

Thanks,  
Joe

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 10:55am UTC](https://discuss.elastic.co/t/user-agent-raw-mapping/59533/2 "2016-09-01T10:55:23Z")

</div>

You need to modify the index template used so that the fields in question are not\_analyzed.

Alternatively, you can aggregate on the .raw subfield that you probably have.

---

<div class="post-metadata">

**Author:** ![JoeeGrigg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joeegrigg/32/4411_2.png) [@JoeeGrigg](https://discuss.elastic.co/u/JoeeGrigg)\
**Post date:** [September 1, 2016, 12:40pm UTC](https://discuss.elastic.co/t/user-agent-raw-mapping/59533/3 "2016-09-01T12:40:00Z")

</div>

There is no raw field and that is how I have seen it being done everywhere else.

Is there any way of forcing that to be added in logstash? or is that an elasticsearch or kibana thing?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 1:32pm UTC](https://discuss.elastic.co/t/user-agent-raw-mapping/59533/4 "2016-09-01T13:32:44Z")

</div>

> There is no raw field and that is how I have seen it being done everywhere else.

I'm guessing your index name doesn't start with "logstash-"?

> Is there any way of forcing that to be added in logstash? or is that an elasticsearch or kibana thing?

It's an Elasticsearch thing, but done upon request from Logstash's default configuration and the index template it pushes to ES (and that template only matches indexes whose names match logstash-\*).

---

<div class="post-metadata">

**Author:** ![JoeeGrigg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joeegrigg/32/4411_2.png) [@JoeeGrigg](https://discuss.elastic.co/u/JoeeGrigg)\
**Post date:** [September 1, 2016, 1:47pm UTC](https://discuss.elastic.co/t/user-agent-raw-mapping/59533/5 "2016-09-01T13:47:10Z")

</div>

Ah okay yeah. I have changed my index name to start with logstash-... and it all works great now.

Thank you for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:40am UTC](https://discuss.elastic.co/t/user-agent-raw-mapping/59533/6 "2017-07-06T04:40:26Z")

</div>


