# Useragent filter not working as expected after enabling ECS

**URL:** <https://discuss.elastic.co/t/useragent-filter-not-working-as-expected-after-enabling-ecs/327662>\
**Category:** Logstash\
**Created:** [March 14, 2023, 12:52pm UTC](https://discuss.elastic.co/t/useragent-filter-not-working-as-expected-after-enabling-ecs/327662 "2023-03-14T12:52:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![flalar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flalar/32/85777_2.png) [@flalar](https://discuss.elastic.co/u/flalar)\
**Post date:** [March 14, 2023, 12:52pm UTC](https://discuss.elastic.co/t/useragent-filter-not-working-as-expected-after-enabling-ecs/327662/1 "2023-03-14T12:52:06Z")

</div>

We're having trouble with the useragent filter not adding the data to the document sent to Elasticsearch or stdout. Seems this happend after enabling support for ECS. Upgrading from Logstash 7.17.9 to 8.6.2 did not solve the issue either.

Filter is configured likt this

```auto
 useragent {
            source => "user_agent_original"           
            add_tag => ["useragent_added"]            
        }

```

example of the source "user\_agent\_original":"Mozilla/5.0 (Linux; Android 13; SM-G781B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Mobile Safari/537.36",

The tag "useragent\_added" is found in the output, but no traces of the useragent

Any tips on how to debug this?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 14, 2023, 1:04pm UTC](https://discuss.elastic.co/t/useragent-filter-not-working-as-expected-after-enabling-ecs/327662/2 "2023-03-14T13:04:42Z")

</div>

> [@flalar](#):
>
> We're having trouble with the useragent filter not adding the data to the document sent to Elasticsearch or stdout.

What trouble? You need to share logs or some kind of evidence, it is not possible to know what is happening with just that information. What do you have in logstash logs? Any WARN or ERROR logs?

> [@flalar](#):
>
> The tag "useragent\_added" is found in the output, but no traces of the useragent

Can you share your output? Also, share your full logstash configuration if possible.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 14, 2023, 8:13pm UTC](https://discuss.elastic.co/t/useragent-filter-not-working-as-expected-after-enabling-ecs/327662/3 "2023-03-14T20:13:13Z")

</div>

Your code is OK.

```auto
   useragent {
            source => "user_agent_original"
            add_tag => ["useragent_added"]
        }

```

LS 8.6.2 will produce :

```auto
"user_agent" => {
       "os" => {
       "name" => "Android",
       "version" => "13",
       "full" => "Android 13"
        },
       "name" => "Chrome Mobile",
       "device" => {
            "name" => "Samsung SM-G781B"
        },
        "version" => "107.0.0.0"
    }

```

You can use this notation, and will get full ECS user\_agent structure

```auto
   useragent {
            source => "[user_agent][original]" # instead of user_agent_original
            target => "user_agent" # the user_agent field name is default and madatory for ECS
            ecs_compatibility => "v8" # v8 is default 
            add_tag => ["useragent_added"]
        }

```

Will get as full ECS:

```auto
    "user_agent" => {
        "original" => "Mozilla/5.0 (Linux; Android 13; SM-G781B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Mobile Safari/537.36",
              "os" => {
               "name" => "Android",
            "version" => "13",
               "full" => "Android 13"
        },
            "name" => "Chrome Mobile",
          "device" => {
            "name" => "Samsung SM-G781B"
        },
         "version" => "107.0.0.0"
    }

```

With `ecs_compatibility => "disabled"` , result will be:

```auto
    "user_agent" => {
             "patch" => "0",
           "os_full" => "Android 13",
          "original" => "Mozilla/5.0 (Linux; Android 13; SM-G781B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Mobile Safari/537.36",
             "major" => "107",
                "os" => "Android",
             "minor" => "0",
        "os_version" => "13",
          "os_major" => "13",
              "name" => "Chrome Mobile",
           "os_name" => "Android",
           "version" => "107.0.0.0",
            "device" => "Samsung SM-G781B"
    }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2023, 8:13pm UTC](https://discuss.elastic.co/t/useragent-filter-not-working-as-expected-after-enabling-ecs/327662/4 "2023-04-11T20:13:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
