# UserAgent Transformation in Logstash

**URL:** <https://discuss.elastic.co/t/useragent-transformation-in-logstash/193548>\
**Category:** Logstash\
**Created:** [August 2, 2019, 1:43pm UTC](https://discuss.elastic.co/t/useragent-transformation-in-logstash/193548 "2019-08-02T13:43:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![chimbu3306](https://avatars.discourse-cdn.com/v4/letter/c/c67d28/32.png) [@chimbu3306](https://discuss.elastic.co/u/chimbu3306)\
**Post date:** [August 2, 2019, 1:43pm UTC](https://discuss.elastic.co/t/useragent-transformation-in-logstash/193548/1 "2019-08-02T13:43:36Z")

</div>

I have the below useragent captured as a string in our application logs, we are publishing this logs to elastic search from logstash and currently storing it as string, We would like to convert this string to json object and store it as json objects in elastic search index, so that it will be easy for us to query it in kibana.

input :

"clientUserAgent": "Mozilla/5.0 (X11; Linux x86\_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.67 Safari/537.36"

Expected output in ES:

"clientUserAgent": {  
"os": {  
"major": null,  
"minor": null,  
"patch": null,  
"family": "Linux",  
"patch\_minor": null  
},  
"device": {  
"brand": null,  
"model": null,  
"family": "Other"  
},  
"user\_agent": {  
"major": "75",  
"minor": "0",  
"patch": "3770",  
"family": "Chrome"  
},  
"string": "Mozilla/5.0 (X11; Linux x86\_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.67 Safari/537.36"  
}

can I able to achieve this using logstash filters and is there any working example ?.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 2, 2019, 1:48pm UTC](https://discuss.elastic.co/t/useragent-transformation-in-logstash/193548/2 "2019-08-02T13:48:28Z")

</div>

> [@chimbu3306](#):
>
> can I able to achieve this using logstash filters

There is a [useragent](https://www.elastic.co/guide/en/logstash/current/plugins-filters-useragent.html) filter that parses these strings.

---

<div class="post-metadata">

**Author:** ![chimbu3306](https://avatars.discourse-cdn.com/v4/letter/c/c67d28/32.png) [@chimbu3306](https://discuss.elastic.co/u/chimbu3306)\
**Post date:** [August 2, 2019, 2:36pm UTC](https://discuss.elastic.co/t/useragent-transformation-in-logstash/193548/3 "2019-08-02T14:36:37Z")

</div>

I tried the useragent filter and can see its filtered all the output into separate objects ,Ideally i want to group everything in clientuseragent json object as in the expected output

{  
"minor" =\> "0",  
"os\_minor" =\> "13",  
"clientCorrelationId" =\> "",  
"os\_major" =\> "10",  
"principalId" =\> "",  
"patch" =\> "3538",  
"file" =\> "ServiceEntryInterceptor.java:31",  
"major" =\> "70",  
"payload" =\> {  
"duration" =\> nil,  
"exception" =\> nil,  
"queryParameters" =\> "",  
"httpStatus" =\> nil,  
"message" =\> "Starting request",  
"httpMethod" =\> "GET",  
"httpStatusCode" =\> nil  
},  
"requestId" =\> "d1fb11ef-b51a-11e9-ac5c-c9c6a729005b",  
"@version" =\> "1",  
"host" =\> "a54d67dd9c10",  
"context" =\> "default",  
"customerId" =\> "",  
"correlationId" =\> "d1fb11ef-b51a-11e9-ac5c-c9c6a729005b",  
"timestamp" =\> "2019-08-02T12:44:00.838+01",  
"clientUserAgent" =\> "Mozilla/5.0 (Macintosh; Intel Mac OS X 10\_13\_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36",  
"os" =\> "Mac OS X",  
"level" =\> "INFO",  
"thread" =\> "http-nio-8080-exec-10",  
"message" =\> "Starting request",  
"tags" =\> [  
[0] "\_grokparsefailure"  
],  
"@timestamp" =\> 2019-08-02T14:32:03.135Z,  
"breadcrumb" =\> "reference:1",  
"application" =\> "reference",  
"principalPermissions" =\> "",  
"build" =\> "",  
"name" =\> "Chrome",  
"os\_name" =\> "Mac OS X",

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 2, 2019, 3:54pm UTC](https://discuss.elastic.co/t/useragent-transformation-in-logstash/193548/4 "2019-08-02T15:54:50Z")

</div>

So specify the target option on the filter. If you don't like the resulting arrangement of fields then use mutate to move them around.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2019, 3:55pm UTC](https://discuss.elastic.co/t/useragent-transformation-in-logstash/193548/5 "2019-08-30T15:55:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
