# Conditional with regex failing

**URL:** <https://discuss.elastic.co/t/conditional-with-regex-failing/272743>\
**Category:** Logstash\
**Created:** [May 11, 2021, 9:04pm UTC](https://discuss.elastic.co/t/conditional-with-regex-failing/272743 "2021-05-11T21:04:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [May 11, 2021, 9:04pm UTC](https://discuss.elastic.co/t/conditional-with-regex-failing/272743/1 "2021-05-11T21:04:12Z")

</div>

Hi Im trying to replace a value whenever the the characters ":" are present in the category field, but I get an error, I tried to scape the colon, but I get an error too

```auto
if [category] =~ /:\\/ { mutate { replace => ["category", "Discos"]}}

```

this is one of the falues in the field category

```auto
MIN-MARC0_E:\Mail-LOG\JLN-MBX01

```

What will be te problem?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 11, 2021, 9:50pm UTC](https://discuss.elastic.co/t/conditional-with-regex-failing/272743/2 "2021-05-11T21:50:05Z")

</div>

> [@ElasticLiver](#):
>
> I get an error

What error do you get?

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [May 11, 2021, 9:55pm UTC](https://discuss.elastic.co/t/conditional-with-regex-failing/272743/3 "2021-05-11T21:55:51Z")

</div>

Hi Badger, this is the error that I get

```auto
  {
    :action=>LogStash: :PipelineAction: :Create/pipeline_id:sitesmincalert,
    :exception=>"LogStash::ConfigurationError",
    :message=>"Expected one of [\\t\\r\\n], \"#\", \"and\", \"or\", \"xor\", \"nand\", \"{\" at line 50, column 20 (byte 1496) after filter {\n\n mutate {\n add_field => { \"fuente\" => \"sitescope\" }\n add_field => { \"severity\" => \"5\" }\n add_field => { \"severity_name\" => \"CRITICAL\" }\n }\n\n mutate {\n convert => {\"severity\" => \"integer\"}\n }\n\n if [grupo] == \"MINJU_URLs Internas\"{\n\t\tmutate {\n\t\tadd_field => { \"category\" => \"urls\" }\n\t\t }\n\t}else{\n\t\tgrok { \n\t\t match => [\"monitor\" , \"%{DATA:cliente}_%{DATA:source}_%{GREEDYDATA:category}\"]\n\t\t match => [\"monitor\" , \"%{DATA:cliente}-%{DATA:source}_%{GREEDYDATA:category}\"]\n\t\t}\n\t}\n\n\tif [category] =~ /Disco_([A-Z])/ { mutate { replace => [\"category\", \"Discos\"]}}\n\n\tif [category] =~ /Filesystem_/ { mutate { replace => [\"category\", \"Discos\"]}}\n\n\tif [category] =~ /:\\\\/ { mutate { replace => [\"category\", \"Discos\"]}}\n\t\n\tif [category] =~ /",
    :backtrace=>[
      "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'",
      "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in `compile_graph'",
      "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'",
      "org/jruby/RubyArray.java:2580:in `map'",
      "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'",
      "org/logstash/execution/AbstractPipelineExt.java:161:in `initialize'",
      "org/logstash/execution/JavaBasePipelineExt.java:47:in `initialize'",
      "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:27:in `initialize'",
      "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:36:in `execute'",
      "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:326:in `block in converge_state'"
    ]
  }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 11, 2021, 10:49pm UTC](https://discuss.elastic.co/t/conditional-with-regex-failing/272743/4 "2021-05-11T22:49:02Z")

</div>

That is an interesting bug. Just as you cannot have a backslash at the end of a quoted string, you cannot have a backslash at the end of a regexp. The parser (as I understand it) uses the second backslash to escape the forward slash and then it all goes pear shaped. The workaround is to match zero or more of any character after the backslash.

```
if [category] =~ /:\\.*/

```

There are multiple related [issues](https://github.com/elastic/logstash/issues/12423) already open on the way the parser treats backslashes in the configuration.

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [May 12, 2021, 1:47am UTC](https://discuss.elastic.co/t/conditional-with-regex-failing/272743/6 "2021-05-12T01:47:34Z")

</div>

interesting in deed, my edit window, and what I really write

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a1010f5f297cdacf25f8c8598d32c6bc5f47ff28.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 12, 2021, 2:22am UTC](https://discuss.elastic.co/t/conditional-with-regex-failing/272743/7 "2021-05-12T02:22:22Z")

</div>

Put back ticks around things to prevent them being interpreted like that. If you write

```
`:\`

```

It will appear as `:\`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2021, 2:23am UTC](https://discuss.elastic.co/t/conditional-with-regex-failing/272743/8 "2021-06-09T02:23:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
