# Wrong phrase in the http.response.phrase field

**URL:** <https://discuss.elastic.co/t/wrong-phrase-in-the-http-response-phrase-field/95182>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [July 31, 2017, 12:08pm UTC](https://discuss.elastic.co/t/wrong-phrase-in-the-http-response-phrase-field/95182 "2017-07-31T12:08:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![KBuev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kbuev/32/20620_2.png) [@KBuev](https://discuss.elastic.co/u/KBuev)\
**Post date:** [July 31, 2017, 12:08pm UTC](https://discuss.elastic.co/t/wrong-phrase-in-the-http-response-phrase-field/95182/1 "2017-07-31T12:08:30Z")

</div>

Hi,

It appears that Packetbeat 5.5.0 (the HTTP module) only gets the last word from HTTP status line when searching for the response phrase.  
`HTTP/1.1 500 Internal Server Error` turns into "[Error](http://i.imgur.com/0cfvQT1.png)" in the `http.response.phrase` field and `HTTP/1.1 404 Not Found` gets parsed as "[Found](http://i.imgur.com/mO38RoD.png)".

Here are some examples of response headers and HTTP status lines (as reported by curl) that were not parsed correctly by Packetbeat:

```
HTTP/1.1 404 Not Found
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=utf-8
Content-Length: 949
Date: Mon, 31 Jul 2017 11:31:53 GMT

HTTP/1.1 500 Internal Server Error
Server: Apache-Coyote/1.1
Content-Type: text/html;charset=utf-8
Content-Length: 3739
Date: Mon, 31 Jul 2017 11:33:28 GMT
Connection: close

```

Apart from the response phrase, I haven't noticed any other erroneous values being reported by Packetbeat.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 31, 2017, 12:13pm UTC](https://discuss.elastic.co/t/wrong-phrase-in-the-http-response-phrase-field/95182/2 "2017-07-31T12:13:22Z")

</div>

That's weird. Can you open [a bug report](https://github.com/elastic/beats/issues), so this can be tracked? Thanks.

---

<div class="post-metadata">

**Author:** ![KBuev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kbuev/32/20620_2.png) [@KBuev](https://discuss.elastic.co/u/KBuev)\
**Post date:** [July 31, 2017, 12:28pm UTC](https://discuss.elastic.co/t/wrong-phrase-in-the-http-response-phrase-field/95182/3 "2017-07-31T12:28:18Z")

</div>

Yep, opened issue #[4795](https://github.com/elastic/beats/issues/4795).

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 1, 2017, 12:05pm UTC](https://discuss.elastic.co/t/wrong-phrase-in-the-http-response-phrase-field/95182/4 "2017-08-01T12:05:03Z")

</div>

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2017, 12:05pm UTC](https://discuss.elastic.co/t/wrong-phrase-in-the-http-response-phrase-field/95182/5 "2017-08-29T12:05:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
