# Visitor user agent information

**URL:** <https://discuss.elastic.co/t/visitor-user-agent-information/250515>\
**Category:** Elasticsearch\
**Created:** [September 30, 2020, 1:51pm UTC](https://discuss.elastic.co/t/visitor-user-agent-information/250515 "2020-09-30T13:51:36Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sandikata](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandikata/32/73421_2.png) [@sandikata](https://discuss.elastic.co/u/sandikata)\
**Post date:** [September 30, 2020, 1:51pm UTC](https://discuss.elastic.co/t/visitor-user-agent-information/250515/1 "2020-09-30T13:51:36Z")

</div>

Hello!

I am trying to separate in fields the useragent information, i've followed instructions from

[user-agent-processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/user-agent-processor.html)

Everything looks good, but when i check in kibana frontend, everything is still on same line, not separated as expected.

```auto
root@elastic-master /usr/share/elasticsearch # curl -X PUT -u elastic: ************"192.168.56.202:9200/_ingest/pipeline/user_agent?pretty" -H 'Content-Type: application/json' -d' 
{
  "description" : "Add user agent information",
  "processors" : [
    {
      "user_agent" : {
        "field" : "agent"
      }
    }
  ]
}
'
{
  "acknowledged" : true
}

```

```auto
root@elastic-master /usr/share/elasticsearch # curl -X PUT -u elastic: *****************"192.168.56.202:9200/my-index-000001/_doc/my_id?pipeline=user_agent&pretty" -H 'Content-Type: application/json' -d'
{
  "agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36"
}                 
'    
{
  "_index" : "my-index-000001",
  "_type" : "_doc",
  "_id" : "my_id",
  "_version" : 1,
  "result" : "created",
  "_shards" : {
    "total" : 2,
    "successful" : 2,
    "failed" : 0
  },
  "_seq_no" : 0,
  "_primary_term" : 89
}

```

```auto
root@elastic-master /usr/share/elasticsearch # curl -X GET -u elastic: *************"192.168.56.202:9200/my-index-000001/_doc/my_id?pretty" 
{
  "_index" : "my-index-000001",
  "_type" : "_doc",
  "_id" : "my_id",
  "_version" : 1,
  "_seq_no" : 0,
  "_primary_term" : 89,
  "found" : true,
  "_source" : {
    "agent" : "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36",
    "user_agent" : {
      "original" : "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36",
      "os" : {
        "name" : "Mac OS X",
        "version" : "10.10.5",
        "full" : "Mac OS X 10.10.5"
      },
      "name" : "Chrome",
      "device" : {
        "name" : "Mac"
      },
      "version" : "51.0.2704.103"
    }
  }
}

```

It works only on new index, but on existing it won't, or i am supposed to check tomorrow on new indicies?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 30, 2020, 9:40pm UTC](https://discuss.elastic.co/t/visitor-user-agent-information/250515/2 "2020-09-30T21:40:40Z")

</div>

Did you try to refresh your index pattern in Kibana?

---

<div class="post-metadata">

**Author:** ![sandikata](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandikata/32/73421_2.png) [@sandikata](https://discuss.elastic.co/u/sandikata)\
**Post date:** [October 1, 2020, 4:47am UTC](https://discuss.elastic.co/t/visitor-user-agent-information/250515/3 "2020-10-01T04:47:13Z")

</div>

I did, and no change at all. Still same like before, in one line. Even new indexes hasn't been changed.

---

<div class="post-metadata">

**Author:** ![sandikata](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandikata/32/73421_2.png) [@sandikata](https://discuss.elastic.co/u/sandikata)\
**Post date:** [October 2, 2020, 11:35am UTC](https://discuss.elastic.co/t/visitor-user-agent-information/250515/4 "2020-10-02T11:35:08Z")

</div>

? Is it there something else hidden which is not mentioned in documentation?

---

<div class="post-metadata">

**Author:** ![sandikata](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandikata/32/73421_2.png) [@sandikata](https://discuss.elastic.co/u/sandikata)\
**Post date:** [October 5, 2020, 5:59am UTC](https://discuss.elastic.co/t/visitor-user-agent-information/250515/5 "2020-10-05T05:59:02Z")

</div>

I've found something, but it not work always, or maybe depend on log format.

---

<div class="post-metadata">

**Author:** ![sandikata](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandikata/32/73421_2.png) [@sandikata](https://discuss.elastic.co/u/sandikata)\
**Post date:** [October 14, 2020, 11:23am UTC](https://discuss.elastic.co/t/visitor-user-agent-information/250515/6 "2020-10-14T11:23:32Z")

</div>

Fixed by adding user\_agent block in logstash grok filter

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2020, 11:23am UTC](https://discuss.elastic.co/t/visitor-user-agent-information/250515/7 "2020-11-11T11:23:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
