# Convert Hexadecimal value to ASCII

**URL:** <https://discuss.elastic.co/t/convert-hexadecimal-value-to-ascii/222408>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring, elastic-stack-security\
**Created:** [March 6, 2020, 6:25am UTC](https://discuss.elastic.co/t/convert-hexadecimal-value-to-ascii/222408 "2020-03-06T06:25:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankitsynX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitsynx/32/64535_2.png) [@ankitsynX](https://discuss.elastic.co/u/ankitsynX)\
**Post date:** [March 6, 2020, 6:25am UTC](https://discuss.elastic.co/t/convert-hexadecimal-value-to-ascii/222408/1 "2020-03-06T06:25:43Z")

</div>

Hi,

I am trying to parse some events from Auditd, the values have been extracted but the commands executed are coming in hexadecimal format.

Can anyone help how to convert it to ASCII in a logstash pipeline using mutate.  
I found a way to convert integer to hex using ruby

mutate { add\_field =\> { "someField" =\> 65533 } }  
ruby { code =\> 'event.set("hexField", event.get("someField").to\_i.to\_s(16))' }

I am not an expert on ruby so not able to do it other way round.

Ankit

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [March 6, 2020, 2:27pm UTC](https://discuss.elastic.co/t/convert-hexadecimal-value-to-ascii/222408/2 "2020-03-06T14:27:36Z")

</div>

Hi there,

doesn't it work the other way round? I mean in ruby:

- 65533.to\_s(16) == "fffd"
- "fffd".to\_i(16) == 65533

Can you post here some samples of this hexadecimal field and how you'd like it to be converted into?

Thanks

---

<div class="post-metadata">

**Author:** ![ankitsynX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitsynx/32/64535_2.png) [@ankitsynX](https://discuss.elastic.co/u/ankitsynX)\
**Post date:** [March 6, 2020, 3:00pm UTC](https://discuss.elastic.co/t/convert-hexadecimal-value-to-ascii/222408/3 "2020-03-06T15:00:39Z")

</div>

Hi Fabio,

69707461626C65732D726573746F7265002D770035002D2D6E6F666C757368002D2D636F756E74657273 (converted value = iptables-restore-w5--noflush--counters )  
66696C6562656174002D65002D7374726963742E7065726D733D66616C7365002D6300636F6E6669672F66696C65626561742E796D6C (converted value = filebeat-e-strict.perms=false-cconfig/filebeat.yml )

There are basically commands in linux logged by auditd in the log files that I am trying to parse.

I wrote a ruby code for conversion as well :  
ruby { code =\> "event.set('command', event.get('command').pack('H\*'))" }

But Logstash is tagging these events as \_rubyexception.  
Also getting below error in LS logs:  
[ERROR] 2020-03-06 14:52:06.405 [[main]\>worker9] ruby - Ruby exception occurred: undefined method `pack' for nil:NilClass

Thanks!

---

<div class="post-metadata">

**Author:** ![ankitsynX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitsynx/32/64535_2.png) [@ankitsynX](https://discuss.elastic.co/u/ankitsynX)\
**Post date:** [March 12, 2020, 2:59pm UTC](https://discuss.elastic.co/t/convert-hexadecimal-value-to-ascii/222408/4 "2020-03-12T14:59:15Z")

</div>

Found the solution here:

ruby { code =\> "event.set('somefield'),event.get('hex-field').split.pack('H\*'))"}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2020, 2:59pm UTC](https://discuss.elastic.co/t/convert-hexadecimal-value-to-ascii/222408/5 "2020-04-09T14:59:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
