# Useragent plugin - android 9 and 10

**URL:** <https://discuss.elastic.co/t/useragent-plugin-android-9-and-10/239175>\
**Category:** Logstash\
**Created:** [June 29, 2020, 7:16pm UTC](https://discuss.elastic.co/t/useragent-plugin-android-9-and-10/239175 "2020-06-29T19:16:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![holiveira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/holiveira/32/100472_2.png) [@holiveira](https://discuss.elastic.co/u/holiveira)\
**Post date:** [June 29, 2020, 7:16pm UTC](https://discuss.elastic.co/t/useragent-plugin-android-9-and-10/239175/1 "2020-06-29T19:16:43Z")

</div>

The parse of an Android 9 or 10 useragent is partial. For example, the fields user\_agentos\_major, user\_agentos\_minor do not exist.

Example useragent:

Mozilla/5.0 (Linux; Android 9; Redmi Note 7 Build/PKQ1.180904.001; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/83.0.4103.106 Mobile Safari/537.36

Mozilla/5.0 (Linux; Android 10; moto g(7) play Build/QPY30.52-22; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/80.0.3987.149 Mobile Safari/537.36

Plugin version: logstash-filter-useragent (3.2.4)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 29, 2020, 8:38pm UTC](https://discuss.elastic.co/t/useragent-plugin-android-9-and-10/239175/2 "2020-06-29T20:38:35Z")

</div>

> [@holiveira](#):
>
> The parse of an Android 9 or 10 useragent is partial.

That feels like a bug to me. The regex ([here](https://github.com/ua-parser/uap-core/blob/f21592418f6323f9ce32f10e231841cf8e782b43/regexes.yaml#L1051)) has two capture groups, which set the os name and os\_major\_version. However, the filter [appears](https://github.com/logstash-plugins/logstash-filter-useragent/blob/3f50c35e77fd1d8730be063f2acfd8dbf551d174/lib/logstash/filters/useragent.rb#L132) to only set the os\_major\_version if it also has os\_minor\_version!

```
if os.minor && os.major
    event.set(@prefixed_os_major, os.major.dup.force_encoding(Encoding::UTF_8)) if os.major
    event.set(@prefixed_os_minor, os.minor.dup.force_encoding(Encoding::UTF_8)) if os.minor
end

```

makes no sense to me. Both event.set calls are conditional on things that have just been tested and proven true. Perhaps

```
if os.minor || os.major

```

was intended. Or maybe

```
if os.major
    event.set(@prefixed_os_major, os.major.dup.force_encoding(Encoding::UTF_8))
    event.set(@prefixed_os_minor, os.minor.dup.force_encoding(Encoding::UTF_8)) if os.minor
end

```

It is anybody's guess.

---

<div class="post-metadata">

**Author:** ![holiveira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/holiveira/32/100472_2.png) [@holiveira](https://discuss.elastic.co/u/holiveira)\
**Post date:** [July 6, 2020, 11:20am UTC](https://discuss.elastic.co/t/useragent-plugin-android-9-and-10/239175/3 "2020-07-06T11:20:36Z")

</div>

Any workaround?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 6, 2020, 4:58pm UTC](https://discuss.elastic.co/t/useragent-plugin-android-9-and-10/239175/4 "2020-07-06T16:58:40Z")

</div>

I cannot think of one.

---

<div class="post-metadata">

**Author:** ![holiveira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/holiveira/32/100472_2.png) [@holiveira](https://discuss.elastic.co/u/holiveira)\
**Post date:** [July 9, 2020, 10:49am UTC](https://discuss.elastic.co/t/useragent-plugin-android-9-and-10/239175/5 "2020-07-09T10:49:32Z")

</div>

There is already an open [issue](https://github.com/logstash-plugins/logstash-filter-useragent/issues/65) about this problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2020, 10:49am UTC](https://discuss.elastic.co/t/useragent-plugin-android-9-and-10/239175/6 "2020-08-06T10:49:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
