# A single backslash becomes double backslash

**URL:** <https://discuss.elastic.co/t/a-single-backslash-becomes-double-backslash/151202>\
**Category:** Logstash\
**Created:** [October 5, 2018, 11:38am UTC](https://discuss.elastic.co/t/a-single-backslash-becomes-double-backslash/151202 "2018-10-05T11:38:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nww\_Pot\_Fung\_Nng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nww_pot_fung_nng/32/128628_2.png) [@Nww\_Pot\_Fung\_Nng](https://discuss.elastic.co/u/Nww_Pot_Fung_Nng)\
**Post date:** [October 5, 2018, 11:38am UTC](https://discuss.elastic.co/t/a-single-backslash-becomes-double-backslash/151202/1 "2018-10-05T11:38:14Z")

</div>

I have messages which contain computer name under Windows domain. The format will be domain\computername. However, the message ends up domain\\computername in elasticsearch indice. When I do a search, I need to put domain\\\\computername in my query. Is it the expected behavior?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 5, 2018, 1:32pm UTC](https://discuss.elastic.co/t/a-single-backslash-becomes-double-backslash/151202/2 "2018-10-05T13:32:37Z")

</div>

Where are you seeing the double backslashes? Show a screenshot or dump the raw JSON document.

---

<div class="post-metadata">

**Author:** ![Nww\_Pot\_Fung\_Nng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nww_pot_fung_nng/32/128628_2.png) [@Nww\_Pot\_Fung\_Nng](https://discuss.elastic.co/u/Nww_Pot_Fung_Nng)\
**Post date:** [October 5, 2018, 2:56pm UTC](https://discuss.elastic.co/t/a-single-backslash-becomes-double-backslash/151202/3 "2018-10-05T14:56:17Z")

</div>

My CSV file:  
`2018-10-05T09:05:03+0800,NHS\WARD-0147-A,admin,SCOTT,sqlplus.exe`

Query:

```
curl -X VIEW http://localhost:9200/logstash-audit-2018.10.05/_search?pretty -H 'Cache-Control: no-cache' -H 'Content-Type: application/json' -d '{
  "query": {
    "query_string": {
     "query": "sid:ORCL1 AND dbuser:SCOTT AND osuser:admin AND module:sqlplus.exe"
    }
  }
}'

```

Results:

```
{
  "took" : 1,
  "timed_out" : false,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : 1,
    "max_score" : 6.2808843,
    "hits" : [
      {
        "_index" : "logstash-audit-2018.10.05",
        "_type" : "doc",
        "_id" : "chvGQWYB_VzXwqnenfyE",
        "_score" : 6.2808843,
        "_source" : {
          "@timestamp" : "2018-10-05T01:05:03.000Z",
          "userhost" : "NHS\\WARD-0147-A",
          "sid" : "ORCL1",
          "return_code" : "",
          "file" : "/appl/audit/ORCL1/20181005091000.txt",
          "offset" : "92",
          "format" : "csv",
          "osuser" : "admin",
          "dbuser" : "SCOTT",
          "module" : "sqlplus.exe",
          "known_source" : "true",
          "@version" : "1",
          "host" : "dbserver1",
          "localtime" : "2018-10-05 09:05:03",
          "message" : "2018-10-05T09:05:03+0800,NHS\\WARD-0147-A,admin,SCOTT,sqlplus.exe",
          "tags" : [
            "audit",
            "known_source"
          ],
          "log_timestamp" : "2018-10-05T09:05:03+0800",
          "type" : "audit"
        }
      }
    ]
  }
}

```

Query:

```
curl -X VIEW http://localhost:9200/logstash-audit-2018.10.05/_search?pretty -H 'Cache-Control: no-cache' -H 'Content-Type: application/json' -d '{
  "query": {
    "query_string": {
     "query": "sid:ORCL1 AND dbuser:SCOTT AND osuser:admin AND module:sqlplus.exe AND userhost:NHS\\WARD-0147-A"
    }
  }
}'

```

Result:

```
{
  "took" : 1,
  "timed_out" : false,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : 0,
    "max_score" : null,
    "hits" : []
  }
}

```

In Kibana, one backslash is displayed under the Table tab. Under JSON tab, it shows double backslash.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 5, 2018, 4:41pm UTC](https://discuss.elastic.co/t/a-single-backslash-becomes-double-backslash/151202/4 "2018-10-05T16:41:32Z")

</div>

Everything's fine. You need four backslashes in your query because both the JSON serialization and the query language require backslashes to be escaped.

---

<div class="post-metadata">

**Author:** ![Nww\_Pot\_Fung\_Nng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nww_pot_fung_nng/32/128628_2.png) [@Nww\_Pot\_Fung\_Nng](https://discuss.elastic.co/u/Nww_Pot_Fung_Nng)\
**Post date:** [October 6, 2018, 1:24am UTC](https://discuss.elastic.co/t/a-single-backslash-becomes-double-backslash/151202/5 "2018-10-06T01:24:31Z")

</div>

Right. It's the JSON serialization. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2018, 1:24am UTC](https://discuss.elastic.co/t/a-single-backslash-becomes-double-backslash/151202/6 "2018-11-03T01:24:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
