ECS Field Reference
ECS 1.12
User agent
⚠️ Outdated Version: You are viewing ECS version 1.12, which is outdated. View the latest version (9.0)
ECS Version:

User agent

Fields to describe a browser user_agent string.

Fields

Field Summary

FieldTypeLevelDescription
user_agent.device.namekeywordExtendedName of the device.
user_agent.namekeywordExtendedName of the user agent.
user_agent.originalkeywordExtendedUnparsed user_agent string.
user_agent.original.textmatch_only_textExtendedUnparsed user_agent string.
user_agent.os.familykeywordExtendedOS family (such as redhat, debian, freebsd, windows).
user_agent.os.fullkeywordExtendedOperating system name, including the version or code name.
user_agent.os.full.textmatch_only_textExtendedOperating system name, including the version or code name.
user_agent.os.kernelkeywordExtendedOperating system kernel version as a raw string.
user_agent.os.namekeywordExtendedOperating system name, without the version.
user_agent.os.name.textmatch_only_textExtendedOperating system name, without the version.
user_agent.os.platformkeywordExtendedOperating system platform (such centos, ubuntu, windows).
user_agent.os.typekeywordExtendedWhich commercial OS family (one of: linux, macos, unix or windows).
user_agent.os.versionkeywordExtendedOperating system version as a raw string.
user_agent.versionkeywordExtendedVersion of the user agent.

Field Details

user_agent.device.name

Type: keyword

Level: Extended

Description: Name of the device.

Example: iPhone

Indexed: true

user_agent.name

Type: keyword

Level: Extended

Description: Name of the user agent.

Example: Safari

Indexed: true

user_agent.original

Type: keyword

Level: Extended

Description: Unparsed user_agent string.

Example: Mozilla/5.0 (iPhone; CPU iPhone OS 12_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0 Mobile/15E148 Safari/604.1

Indexed: true

user_agent.original.text

Type: match_only_text

Level: Extended

Description: Unparsed user_agent string.

Example: Mozilla/5.0 (iPhone; CPU iPhone OS 12_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0 Mobile/15E148 Safari/604.1

Indexed: true

user_agent.os.family

Type: keyword

Level: Extended

Description: OS family (such as redhat, debian, freebsd, windows).

Example: debian

Indexed: true

user_agent.os.full

Type: keyword

Level: Extended

Description: Operating system name, including the version or code name.

Example: Mac OS Mojave

Indexed: true

user_agent.os.full.text

Type: match_only_text

Level: Extended

Description: Operating system name, including the version or code name.

Example: Mac OS Mojave

Indexed: true

user_agent.os.kernel

Type: keyword

Level: Extended

Description: Operating system kernel version as a raw string.

Example: 4.4.0-112-generic

Indexed: true

user_agent.os.name

Type: keyword

Level: Extended

Description: Operating system name, without the version.

Example: Mac OS X

Indexed: true

user_agent.os.name.text

Type: match_only_text

Level: Extended

Description: Operating system name, without the version.

Example: Mac OS X

Indexed: true

user_agent.os.platform

Type: keyword

Level: Extended

Description: Operating system platform (such centos, ubuntu, windows).

Example: darwin

Indexed: true

user_agent.os.type

Type: keyword

Level: Extended

Description: Which commercial OS family (one of: linux, macos, unix or windows).

Example: macos

Indexed: true

user_agent.os.version

Type: keyword

Level: Extended

Description: Operating system version as a raw string.

Example: 10.14.1

Indexed: true

user_agent.version

Type: keyword

Level: Extended

Description: Version of the user agent.

Example: 12.0

Indexed: true