What is user-agent information in a cloud log?¶
A user agent is a value sent by connecting software that may describe a browser, operating system, application or automated client. It helps compare access routes but rarely identifies one physical device.
Preserve raw and interpreted values¶
Providers may parse the string into browser and operating-system labels. Keep the original string as well because parser changes can alter the displayed interpretation.
Millions of devices share common values. Applications can simplify, modify or imitate them, and privacy features may reduce detail. A change may indicate another client, an update, automation or unauthorised access.
Use the pattern with stronger identifiers¶
Compare user agent across session events and with application IDs, device identifiers, managed-device records and device artefacts. Repetition shows consistency, not uniqueness.
If it identifies an API or sync client, assess whether the event was background activity rather than interactive browser use.
The point to remember
A user agent describes connecting software. Preserve it exactly and use it comparatively with session, application and device evidence.