# Useragent is missing ELB-HealthChecker

**URL:** <https://discuss.elastic.co/t/useragent-is-missing-elb-healthchecker/121143>\
**Category:** Logstash\
**Created:** [February 22, 2018, 11:27pm UTC](https://discuss.elastic.co/t/useragent-is-missing-elb-healthchecker/121143 "2018-02-22T23:27:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![red888](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@red888](https://discuss.elastic.co/u/red888)\
**Post date:** [February 22, 2018, 11:27pm UTC](https://discuss.elastic.co/t/useragent-is-missing-elb-healthchecker/121143/1 "2018-02-22T23:27:00Z")

</div>

Im using the useragent plugin in my logstash pipeline:  
useragent {  
prefix =\> "userAgent\_"  
source =\> "userAgent"  
}

But its not getting the ELB healthcheck user agent

Here is an example log line:  
`2018-02-22 14:53:31 W3SVC2 myserver 1.1.1.1 GET /index.html - 7777 - 2.2.2.2 HTTP/1.1 ELB-HealthChecker/1.0 - - 1.1.1.1:7777 200 0 0 310 124 2 - - -`

so `ELB-HealthChecker/1.0` is showing up in kibana as "other".

Can I work around this or add a custom agent if the plugin doesn't have it? Id really like this to show up as the elb healthcheck in kibana.

Thanks for any help!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 23, 2018, 2:02pm UTC](https://discuss.elastic.co/t/useragent-is-missing-elb-healthchecker/121143/2 "2018-02-23T14:02:04Z")

</div>

Have a look at the plugin's `regexes` option.

---

<div class="post-metadata">

**Author:** ![red888](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@red888](https://discuss.elastic.co/u/red888)\
**Post date:** [February 23, 2018, 7:57pm UTC](https://discuss.elastic.co/t/useragent-is-missing-elb-healthchecker/121143/3 "2018-02-23T19:57:58Z")

</div>

wow im looking at: [https://github.com/ua-parser/uap-core/blob/master/regexes.yaml](https://github.com/ua-parser/uap-core/blob/master/regexes.yaml)

I've decided to just drop lines with this useragent but in the future i guess I could just send a pull request to add it?

---

<div class="post-metadata">

**Author:** ![red888](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@red888](https://discuss.elastic.co/u/red888)\
**Post date:** [February 26, 2018, 12:03am UTC](https://discuss.elastic.co/t/useragent-is-missing-elb-healthchecker/121143/4 "2018-02-26T00:03:15Z")

</div>

Is there a way to just add a regex without creating my own version of the regexes.yaml file?

Maybe i could just mutate this

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 26, 2018, 6:55am UTC](https://discuss.elastic.co/t/useragent-is-missing-elb-healthchecker/121143/5 "2018-02-26T06:55:19Z")

</div>

I think you'll have to supply your own copy of the file.

---

<div class="post-metadata">

**Author:** ![red888](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@red888](https://discuss.elastic.co/u/red888)\
**Post date:** [February 26, 2018, 11:04pm UTC](https://discuss.elastic.co/t/useragent-is-missing-elb-healthchecker/121143/6 "2018-02-26T23:04:53Z")

</div>

mutate it is! i have 3 custom user agents, hopefully 3 mutate calls won't slow things down in my logstash pipeline

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 26, 2018, 11:04pm UTC](https://discuss.elastic.co/t/useragent-is-missing-elb-healthchecker/121143/7 "2018-03-26T23:04:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
