# Backslashes in the query string JSONs not supported?

**URL:** <https://discuss.elastic.co/t/backslashes-in-the-query-string-jsons-not-supported/69841>\
**Category:** Logstash\
**Created:** [December 22, 2016, 7:40pm UTC](https://discuss.elastic.co/t/backslashes-in-the-query-string-jsons-not-supported/69841 "2016-12-22T19:40:53Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dom-nik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dom-nik/32/13243_2.png) [@Dom-nik](https://discuss.elastic.co/u/Dom-nik)\
**Post date:** [December 22, 2016, 7:40pm UTC](https://discuss.elastic.co/t/backslashes-in-the-query-string-jsons-not-supported/69841/1 "2016-12-22T19:40:54Z")

</div>

I'm having a hard time using the elasticsearch filter plugin, but it seems that the problem is more generic (Logstash JSON parser seems not to understand backslashes in the query strings that it passes to ES), so I'm posting it here too.

- Version: ES/Logstash 5.0.2, elasticsearch filter plugin: 3.1.0
- Operating System: CentOS 7
- Config File (the query I used is in the comment):

```ruby
input {
        elasticsearch {
                hosts => "10.x.y.z:9200"
                index => "data_for_mapping_test"
                query => '
{
  "query": {
    "term": {
      "_id": {
        "value": "1"
      }
    }
  }
}
'
        }
}

filter {
     elasticsearch {
              hosts => ["10.x.y.z:9200"]
              index => "mappings"
              query_template => "/etc/logstash/conf.d/mapping_test.dsl"
              # query => '{ "query": { "term": { "AssetType": "%{AssetType}"} } }'
              fields => {"AssetTypeGrouping" => "AssetTypeGroupingMapped"}
              enable_sort => false
     }
}

output {
    elasticsearch {
        hosts => ["10.x.y.z:9200"]
        index => "mappings_test"
    }
}

```

- Sample Data:  
My input data contains a field like this: `"AssetType":"\\Demo\\Something"`  
My `mappings` index contains documents like this:

```json
{
        "AssetType": "\\Demo\\Something",
        "AssetTypeGrouping": "marketing assets"
}

```

- Steps to Reproduce: Run the pipe ;]
- Error:

> :error=\>#\<LogStash::Json::ParserError: Unrecognized character escape 'D' [...]

**NOTE** : It helped (worked as expected) when I added the following step in the query parsing in the plugin code:

```ruby
query_tmp = event.sprintf(@query_dsl).gsub!('\\', '\\\\\\')

```

So it seems that the **Logstash JSON parser doesn't understand backslashes in the query string**.  
Is it the solution or am I doing something completely stupid?

Reference: [Backslashes in the query string not supported? · Issue #55 · logstash-plugins/logstash-filter-elasticsearch · GitHub](https://github.com/logstash-plugins/logstash-filter-elasticsearch/issues/55)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2017, 7:41pm UTC](https://discuss.elastic.co/t/backslashes-in-the-query-string-jsons-not-supported/69841/2 "2017-01-19T19:41:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
