From 9b9db7d1071234c541f63955d7c47733271cb94a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?No=C3=A9mi=20V=C3=A1nyi?= Date: Tue, 2 Oct 2018 11:55:10 +0200 Subject: [PATCH 1/4] rename user_agent.raw to user_agent.original --- filebeat/docs/fields.asciidoc | 16 ++++++++-------- filebeat/include/fields.go | 2 +- filebeat/module/apache2/access/_meta/fields.yml | 4 ++-- .../module/apache2/access/ingest/default.json | 2 +- .../apache2/access/test/test.log-expected.json | 4 ++-- filebeat/module/iis/access/_meta/fields.yml | 4 ++-- filebeat/module/iis/access/ingest/default.json | 2 +- .../iis/access/test/test.log-expected.json | 6 +++--- filebeat/module/nginx/access/_meta/fields.yml | 4 ++-- filebeat/module/nginx/access/ingest/default.json | 2 +- .../nginx/access/test/test.log-expected.json | 14 +++++++------- filebeat/module/traefik/access/_meta/fields.yml | 4 ++-- .../module/traefik/access/ingest/pipeline.json | 2 +- .../traefik/access/test/test.log-expected.json | 4 ++-- 14 files changed, 35 insertions(+), 35 deletions(-) diff --git a/filebeat/docs/fields.asciidoc b/filebeat/docs/fields.asciidoc index 4869c6899d50..ccc54d0514ee 100644 --- a/filebeat/docs/fields.asciidoc +++ b/filebeat/docs/fields.asciidoc @@ -252,12 +252,12 @@ The name of the operating system. -- -*`apache2.access.user_agent.raw`*:: +*`apache2.access.user_agent.original`*:: + -- type: text -Raw user agent value before parsing by ingest-user-agent plugin. +Original user agent value before parsing by ingest-user-agent plugin. -- @@ -4037,12 +4037,12 @@ The name of the operating system. -- -*`iis.access.user_agent.raw`*:: +*`iis.access.user_agent.original`*:: + -- type: text -Raw user agent value before parsing by ingest-user-agent plugin. +Original user agent value before parsing by ingest-user-agent plugin. -- @@ -5355,12 +5355,12 @@ The name of the operating system. -- -*`nginx.access.user_agent.raw`*:: +*`nginx.access.user_agent.original`*:: + -- type: text -Raw user agent value before parsing by ingest-user-agent plugin. +Original user agent value before parsing by ingest-user-agent plugin. -- @@ -6365,12 +6365,12 @@ The name of the operating system. -- -*`traefik.access.user_agent.raw`*:: +*`traefik.access.user_agent.original`*:: + -- type: text -Raw user agent value before parsing by ingest-user-agent plugin. +Original user agent value before parsing by ingest-user-agent plugin. -- diff --git a/filebeat/include/fields.go b/filebeat/include/fields.go index e42a183f6a2e..4f8a827e7209 100644 --- a/filebeat/include/fields.go +++ b/filebeat/include/fields.go @@ -31,5 +31,5 @@ func init() { // Asset returns asset data func Asset() string { - return "" + return "" } diff --git a/filebeat/module/apache2/access/_meta/fields.yml b/filebeat/module/apache2/access/_meta/fields.yml index 12a87399c534..aef98711450c 100644 --- a/filebeat/module/apache2/access/_meta/fields.yml +++ b/filebeat/module/apache2/access/_meta/fields.yml @@ -85,10 +85,10 @@ type: keyword description: > The name of the operating system. - - name: raw + - name: original type: text description: > - Raw user agent value before parsing by ingest-user-agent plugin. + Original user agent value before parsing by ingest-user-agent plugin. - name: geoip type: group description: > diff --git a/filebeat/module/apache2/access/ingest/default.json b/filebeat/module/apache2/access/ingest/default.json index 1a64fdfd5928..99d2bd8055e5 100644 --- a/filebeat/module/apache2/access/ingest/default.json +++ b/filebeat/module/apache2/access/ingest/default.json @@ -37,7 +37,7 @@ }, { "rename": { "field": "apache2.access.agent", - "target_field": "apache2.access.user_agent.raw", + "target_field": "apache2.access.user_agent.original", "ignore_failure": true } }, { diff --git a/filebeat/module/apache2/access/test/test.log-expected.json b/filebeat/module/apache2/access/test/test.log-expected.json index a8fbd26c0a28..83f1ab65c29b 100644 --- a/filebeat/module/apache2/access/test/test.log-expected.json +++ b/filebeat/module/apache2/access/test/test.log-expected.json @@ -27,11 +27,11 @@ "apache2.access.user_agent.major": "50", "apache2.access.user_agent.minor": "0", "apache2.access.user_agent.name": "Firefox", + "apache2.access.user_agent.original": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:50.0) Gecko/20100101 Firefox/50.0", "apache2.access.user_agent.os": "Mac OS X 10.12", "apache2.access.user_agent.os_major": "10", "apache2.access.user_agent.os_minor": "12", "apache2.access.user_agent.os_name": "Mac OS X", - "apache2.access.user_agent.raw": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:50.0) Gecko/20100101 Firefox/50.0", "apache2.access.user_name": "-", "fileset.module": "apache2", "fileset.name": "access", @@ -63,10 +63,10 @@ "apache2.access.user_agent.major": "15", "apache2.access.user_agent.minor": "0", "apache2.access.user_agent.name": "Firefox Alpha", + "apache2.access.user_agent.original": "Mozilla/5.0 (Windows NT 6.1; rv:15.0) Gecko/20120716 Firefox/15.0a2", "apache2.access.user_agent.os": "Windows 7", "apache2.access.user_agent.os_name": "Windows 7", "apache2.access.user_agent.patch": "a2", - "apache2.access.user_agent.raw": "Mozilla/5.0 (Windows NT 6.1; rv:15.0) Gecko/20120716 Firefox/15.0a2", "apache2.access.user_name": "-", "fileset.module": "apache2", "fileset.name": "access", diff --git a/filebeat/module/iis/access/_meta/fields.yml b/filebeat/module/iis/access/_meta/fields.yml index 12d2906ce3d8..0f2446ce0300 100644 --- a/filebeat/module/iis/access/_meta/fields.yml +++ b/filebeat/module/iis/access/_meta/fields.yml @@ -130,10 +130,10 @@ type: keyword description: > The name of the operating system. - - name: raw + - name: original type: text description: > - Raw user agent value before parsing by ingest-user-agent plugin. + Original user agent value before parsing by ingest-user-agent plugin. - name: geoip type: group description: > diff --git a/filebeat/module/iis/access/ingest/default.json b/filebeat/module/iis/access/ingest/default.json index 6d1c11b83327..4cbe512f5c40 100644 --- a/filebeat/module/iis/access/ingest/default.json +++ b/filebeat/module/iis/access/ingest/default.json @@ -37,7 +37,7 @@ }, { "rename": { "field": "iis.access.agent", - "target_field": "iis.access.user_agent.raw" + "target_field": "iis.access.user_agent.original" } }, { "geoip": { diff --git a/filebeat/module/iis/access/test/test.log-expected.json b/filebeat/module/iis/access/test/test.log-expected.json index 2ef4c983d075..6ee8518bf834 100644 --- a/filebeat/module/iis/access/test/test.log-expected.json +++ b/filebeat/module/iis/access/test/test.log-expected.json @@ -24,9 +24,9 @@ "iis.access.user_agent.major": "57", "iis.access.user_agent.minor": "0", "iis.access.user_agent.name": "Firefox", + "iis.access.user_agent.original": "Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:57.0)+Gecko/20100101+Firefox/57.0", "iis.access.user_agent.os": "Windows", "iis.access.user_agent.os_name": "Windows", - "iis.access.user_agent.raw": "Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:57.0)+Gecko/20100101+Firefox/57.0", "iis.access.user_name": "-", "iis.access.win32_status": "0", "input.type": "log", @@ -55,9 +55,9 @@ "iis.access.user_agent.major": "57", "iis.access.user_agent.minor": "0", "iis.access.user_agent.name": "Firefox", + "iis.access.user_agent.original": "Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:57.0)+Gecko/20100101+Firefox/57.0", "iis.access.user_agent.os": "Windows", "iis.access.user_agent.os_name": "Windows", - "iis.access.user_agent.raw": "Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:57.0)+Gecko/20100101+Firefox/57.0", "iis.access.user_name": "-", "iis.access.win32_status": "0", "input.type": "log", @@ -96,9 +96,9 @@ "iis.access.user_agent.major": "57", "iis.access.user_agent.minor": "0", "iis.access.user_agent.name": "Firefox", + "iis.access.user_agent.original": "Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:57.0)+Gecko/20100101+Firefox/57.0", "iis.access.user_agent.os": "Windows", "iis.access.user_agent.os_name": "Windows", - "iis.access.user_agent.raw": "Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:57.0)+Gecko/20100101+Firefox/57.0", "iis.access.user_name": "-", "iis.access.win32_status": "0", "input.type": "log", diff --git a/filebeat/module/nginx/access/_meta/fields.yml b/filebeat/module/nginx/access/_meta/fields.yml index 70b33affcc69..3669c5f0d31a 100644 --- a/filebeat/module/nginx/access/_meta/fields.yml +++ b/filebeat/module/nginx/access/_meta/fields.yml @@ -92,10 +92,10 @@ type: keyword description: > The name of the operating system. - - name: raw + - name: original type: text description: > - Raw user agent value before parsing by ingest-user-agent plugin. + Original user agent value before parsing by ingest-user-agent plugin. - name: geoip type: group description: > diff --git a/filebeat/module/nginx/access/ingest/default.json b/filebeat/module/nginx/access/ingest/default.json index da2ed31f76e8..dfeae281f08d 100644 --- a/filebeat/module/nginx/access/ingest/default.json +++ b/filebeat/module/nginx/access/ingest/default.json @@ -61,7 +61,7 @@ }, { "rename": { "field": "nginx.access.agent", - "target_field": "nginx.access.user_agent.raw" + "target_field": "nginx.access.user_agent.original" } }, { "geoip": { diff --git a/filebeat/module/nginx/access/test/test.log-expected.json b/filebeat/module/nginx/access/test/test.log-expected.json index 0b7cc7071113..174509327cfa 100644 --- a/filebeat/module/nginx/access/test/test.log-expected.json +++ b/filebeat/module/nginx/access/test/test.log-expected.json @@ -20,11 +20,11 @@ "nginx.access.user_agent.major": "49", "nginx.access.user_agent.minor": "0", "nginx.access.user_agent.name": "Firefox", + "nginx.access.user_agent.original": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:49.0) Gecko/20100101 Firefox/49.0", "nginx.access.user_agent.os": "Mac OS X 10.12", "nginx.access.user_agent.os_major": "10", "nginx.access.user_agent.os_minor": "12", "nginx.access.user_agent.os_name": "Mac OS X", - "nginx.access.user_agent.raw": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:49.0) Gecko/20100101 Firefox/49.0", "nginx.access.user_name": "-", "offset": 0, "prospector.type": "log" @@ -48,10 +48,10 @@ "nginx.access.user_agent.major": "15", "nginx.access.user_agent.minor": "0", "nginx.access.user_agent.name": "Firefox Alpha", + "nginx.access.user_agent.original": "Mozilla/5.0 (Windows NT 6.1; rv:15.0) Gecko/20120716 Firefox/15.0a2", "nginx.access.user_agent.os": "Windows 7", "nginx.access.user_agent.os_name": "Windows 7", "nginx.access.user_agent.patch": "a2", - "nginx.access.user_agent.raw": "Mozilla/5.0 (Windows NT 6.1; rv:15.0) Gecko/20120716 Firefox/15.0a2", "nginx.access.user_name": "-", "offset": 183, "prospector.type": "log" @@ -84,11 +84,11 @@ "nginx.access.user_agent.major": "49", "nginx.access.user_agent.minor": "0", "nginx.access.user_agent.name": "Firefox", + "nginx.access.user_agent.original": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:49.0) Gecko/20100101 Firefox/49.0", "nginx.access.user_agent.os": "Mac OS X 10.12", "nginx.access.user_agent.os_major": "10", "nginx.access.user_agent.os_minor": "12", "nginx.access.user_agent.os_name": "Mac OS X", - "nginx.access.user_agent.raw": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:49.0) Gecko/20100101 Firefox/49.0", "nginx.access.user_name": "-", "offset": 341, "prospector.type": "log" @@ -119,11 +119,11 @@ "nginx.access.user_agent.major": "49", "nginx.access.user_agent.minor": "0", "nginx.access.user_agent.name": "Firefox", + "nginx.access.user_agent.original": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:49.0) Gecko/20100101 Firefox/49.0", "nginx.access.user_agent.os": "Mac OS X 10.12", "nginx.access.user_agent.os_major": "10", "nginx.access.user_agent.os_minor": "12", "nginx.access.user_agent.os_name": "Mac OS X", - "nginx.access.user_agent.raw": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:49.0) Gecko/20100101 Firefox/49.0", "nginx.access.user_name": "-", "offset": 527, "prospector.type": "log" @@ -155,9 +155,9 @@ "nginx.access.url": "/assets/xxxx?q=100", "nginx.access.user_agent.device": "Other", "nginx.access.user_agent.name": "Other", + "nginx.access.user_agent.original": "Amazon CloudFront", "nginx.access.user_agent.os": "Other", "nginx.access.user_agent.os_name": "Other", - "nginx.access.user_agent.raw": "Amazon CloudFront", "nginx.access.user_name": "-", "offset": 693, "prospector.type": "log" @@ -187,9 +187,9 @@ "nginx.access.user_agent.major": "1", "nginx.access.user_agent.minor": "0", "nginx.access.user_agent.name": "Facebot", + "nginx.access.user_agent.original": "Mozilla/5.0 (compatible; Facebot 1.0; https://developers.facebook.com/docs/sharing/webmasters/crawler)", "nginx.access.user_agent.os": "Other", "nginx.access.user_agent.os_name": "Other", - "nginx.access.user_agent.raw": "Mozilla/5.0 (compatible; Facebot 1.0; https://developers.facebook.com/docs/sharing/webmasters/crawler)", "nginx.access.user_name": "-", "offset": 845, "prospector.type": "log" @@ -208,9 +208,9 @@ "nginx.access.response_code": "400", "nginx.access.user_agent.device": "Other", "nginx.access.user_agent.name": "Other", + "nginx.access.user_agent.original": "-", "nginx.access.user_agent.os": "Other", "nginx.access.user_agent.os_name": "Other", - "nginx.access.user_agent.raw": "-", "nginx.access.user_name": "-", "offset": 1085, "prospector.type": "log" diff --git a/filebeat/module/traefik/access/_meta/fields.yml b/filebeat/module/traefik/access/_meta/fields.yml index 15ea1f675db8..a030c9f655c3 100644 --- a/filebeat/module/traefik/access/_meta/fields.yml +++ b/filebeat/module/traefik/access/_meta/fields.yml @@ -85,10 +85,10 @@ type: keyword description: > The name of the operating system. - - name: raw + - name: original type: text description: > - Raw user agent value before parsing by ingest-user-agent plugin. + Original user agent value before parsing by ingest-user-agent plugin. - name: geoip type: group description: > diff --git a/filebeat/module/traefik/access/ingest/pipeline.json b/filebeat/module/traefik/access/ingest/pipeline.json index 7516b3025507..d15899fc98a0 100644 --- a/filebeat/module/traefik/access/ingest/pipeline.json +++ b/filebeat/module/traefik/access/ingest/pipeline.json @@ -50,7 +50,7 @@ { "rename": { "field": "traefik.access.agent", - "target_field": "traefik.access.user_agent.raw" + "target_field": "traefik.access.user_agent.original" } }, { diff --git a/filebeat/module/traefik/access/test/test.log-expected.json b/filebeat/module/traefik/access/test/test.log-expected.json index 5d9df6d28540..27d3066994df 100644 --- a/filebeat/module/traefik/access/test/test.log-expected.json +++ b/filebeat/module/traefik/access/test/test.log-expected.json @@ -17,10 +17,10 @@ "traefik.access.user_agent.major": "61", "traefik.access.user_agent.minor": "0", "traefik.access.user_agent.name": "Chrome", + "traefik.access.user_agent.original": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36", "traefik.access.user_agent.os": "Linux", "traefik.access.user_agent.os_name": "Linux", "traefik.access.user_agent.patch": "3163", - "traefik.access.user_agent.raw": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36", "traefik.access.user_name": "-" }, { @@ -48,10 +48,10 @@ "traefik.access.user_agent.major": "61", "traefik.access.user_agent.minor": "0", "traefik.access.user_agent.name": "Chrome", + "traefik.access.user_agent.original": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36", "traefik.access.user_agent.os": "Linux", "traefik.access.user_agent.os_name": "Linux", "traefik.access.user_agent.patch": "3163", - "traefik.access.user_agent.raw": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36", "traefik.access.user_name": "-" } ] \ No newline at end of file From 3b450ed31f2d0b9ae9a0c004a0b58b3b37beda8a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?No=C3=A9mi=20V=C3=A1nyi?= Date: Wed, 3 Oct 2018 11:49:11 +0200 Subject: [PATCH 2/4] add changelog entry --- CHANGELOG.asciidoc | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGELOG.asciidoc b/CHANGELOG.asciidoc index 70fa946cd7ea..cf4472c57239 100644 --- a/CHANGELOG.asciidoc +++ b/CHANGELOG.asciidoc @@ -123,6 +123,7 @@ https://github.com/elastic/beats/compare/v6.4.0...master[Check the HEAD diff] - Add tag "multiline" to "log.flags" if event consists of multiple lines. {pull}7997[7997] - Add haproxy module. {pull}8014[8014] - Release `docker` input as GA. {pull}8328[8328] +- Rename user_agent.raw to user_ageint.original to follow ECS conventions. {pull}8537[8537] *Heartbeat* From a0cf81e870d953a7fcc8dbe5019e9423d6ca1b36 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?No=C3=A9mi=20V=C3=A1nyi?= Date: Wed, 3 Oct 2018 15:41:32 +0200 Subject: [PATCH 3/4] edit changelog --- CHANGELOG.asciidoc | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/CHANGELOG.asciidoc b/CHANGELOG.asciidoc index cf4472c57239..c4f29e5ebb90 100644 --- a/CHANGELOG.asciidoc +++ b/CHANGELOG.asciidoc @@ -117,13 +117,12 @@ https://github.com/elastic/beats/compare/v6.4.0...master[Check the HEAD diff] - Make inputsource generic taking bufio.SplitFunc as input {pull}7746[7746] - Add custom unpack to log hints config to avoid env resolution {pull}7710[7710] -- Keep raw user agent information after parsing as user_agent_raw in Filebeat modules. {pull}7823[7832] - Make docker input check if container strings are empty {pull}7960[7960] - Add tag "truncated" to "log.flags" if incoming line is longer than configured limit. {pull}7991[7991] - Add tag "multiline" to "log.flags" if event consists of multiple lines. {pull}7997[7997] - Add haproxy module. {pull}8014[8014] - Release `docker` input as GA. {pull}8328[8328] -- Rename user_agent.raw to user_ageint.original to follow ECS conventions. {pull}8537[8537] +- Keep unparsed user agent information in user_agent.original. {pull}8537[8537] *Heartbeat* From 5aa626017f878e2993b679552c177b5bc3a36057 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?No=C3=A9mi=20V=C3=A1nyi?= Date: Wed, 3 Oct 2018 15:41:46 +0200 Subject: [PATCH 4/4] do not index user_agent.original --- filebeat/docs/fields.asciidoc | 8 ++++++++ filebeat/include/fields.go | 2 +- filebeat/module/apache2/access/_meta/fields.yml | 1 + filebeat/module/iis/access/_meta/fields.yml | 1 + filebeat/module/nginx/access/_meta/fields.yml | 1 + filebeat/module/traefik/access/_meta/fields.yml | 1 + 6 files changed, 13 insertions(+), 1 deletion(-) diff --git a/filebeat/docs/fields.asciidoc b/filebeat/docs/fields.asciidoc index ccc54d0514ee..9b4eaf628a6d 100644 --- a/filebeat/docs/fields.asciidoc +++ b/filebeat/docs/fields.asciidoc @@ -260,6 +260,8 @@ type: text Original user agent value before parsing by ingest-user-agent plugin. +Field is not indexed. + -- [float] @@ -4045,6 +4047,8 @@ type: text Original user agent value before parsing by ingest-user-agent plugin. +Field is not indexed. + -- [float] @@ -5363,6 +5367,8 @@ type: text Original user agent value before parsing by ingest-user-agent plugin. +Field is not indexed. + -- [float] @@ -6373,6 +6379,8 @@ type: text Original user agent value before parsing by ingest-user-agent plugin. +Field is not indexed. + -- [float] diff --git a/filebeat/include/fields.go b/filebeat/include/fields.go index 4f8a827e7209..bedd2cfc9a74 100644 --- a/filebeat/include/fields.go +++ b/filebeat/include/fields.go @@ -31,5 +31,5 @@ func init() { // Asset returns asset data func Asset() string { - return "" + return "" } diff --git a/filebeat/module/apache2/access/_meta/fields.yml b/filebeat/module/apache2/access/_meta/fields.yml index aef98711450c..7435e0595340 100644 --- a/filebeat/module/apache2/access/_meta/fields.yml +++ b/filebeat/module/apache2/access/_meta/fields.yml @@ -87,6 +87,7 @@ The name of the operating system. - name: original type: text + index: false description: > Original user agent value before parsing by ingest-user-agent plugin. - name: geoip diff --git a/filebeat/module/iis/access/_meta/fields.yml b/filebeat/module/iis/access/_meta/fields.yml index 0f2446ce0300..6167860b515d 100644 --- a/filebeat/module/iis/access/_meta/fields.yml +++ b/filebeat/module/iis/access/_meta/fields.yml @@ -132,6 +132,7 @@ The name of the operating system. - name: original type: text + index: false description: > Original user agent value before parsing by ingest-user-agent plugin. - name: geoip diff --git a/filebeat/module/nginx/access/_meta/fields.yml b/filebeat/module/nginx/access/_meta/fields.yml index 3669c5f0d31a..58fd4d6d04b0 100644 --- a/filebeat/module/nginx/access/_meta/fields.yml +++ b/filebeat/module/nginx/access/_meta/fields.yml @@ -94,6 +94,7 @@ The name of the operating system. - name: original type: text + index: false description: > Original user agent value before parsing by ingest-user-agent plugin. - name: geoip diff --git a/filebeat/module/traefik/access/_meta/fields.yml b/filebeat/module/traefik/access/_meta/fields.yml index a030c9f655c3..a65e524b057b 100644 --- a/filebeat/module/traefik/access/_meta/fields.yml +++ b/filebeat/module/traefik/access/_meta/fields.yml @@ -87,6 +87,7 @@ The name of the operating system. - name: original type: text + index: false description: > Original user agent value before parsing by ingest-user-agent plugin. - name: geoip