# Cp865 encoded logs

**URL:** <https://discuss.elastic.co/t/cp865-encoded-logs/152238>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 12, 2018, 12:41pm UTC](https://discuss.elastic.co/t/cp865-encoded-logs/152238 "2018-10-12T12:41:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![eikeskog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eikeskog/32/22481_2.png) [@eikeskog](https://discuss.elastic.co/u/eikeskog)\
**Post date:** [October 12, 2018, 12:41pm UTC](https://discuss.elastic.co/t/cp865-encoded-logs/152238/1 "2018-10-12T12:41:05Z")

</div>

Hi,  
Some of the files I am trying to read are encoded in [cp865](https://en.wikipedia.org/wiki/Code_page_865).  
I tried to set encoding: "cp865", but it seems that cp865 is not supported.

_# Configure the file encoding for reading files with international characters_  
\_ # following the W3C recommendation for HTML5 ([http://www.w3.org/TR/encoding](http://www.w3.org/TR/encoding)).\_  
\_ # Some sample encodings:\_  
\_ # plain, utf-8, utf-16be-bom, utf-16be, utf-16le, big5, gb18030, gbk,\_  
\_ # hz-gb-2312, euc-kr, euc-jp, iso-2022-jp, shift-jis, ...\_  
\_ # encoding: utf-8\_

I have tried other encodings, but none will output the Nordic characters correctly.  
Using filebeat-5.6.2  
input\_type: log  
output.redis

What are my options here?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 15, 2018, 11:41pm UTC](https://discuss.elastic.co/t/cp865-encoded-logs/152238/2 "2018-10-15T23:41:27Z")

</div>

Checking our dependencies, IBM865 (CP 865) is defined, but it's no official HTML5 encoding, that's why it's not included in the tables ☹

A many other IBM encodings are missing as well. Please open a [github issue](https://github.com/elastic/beats/issues%5D) about missing codecs in filebeat.

Potential workaround. This is quite hacky and might actually not work out (I'd prefer to fix the bug in filebeat):  
As filebeat already reads the contents and tries to serialize it to UTF-8, we'd have to use some 8bit code map, which is ASCII compatible for all values up to `0x7f`. Reading with utf-8 codec might combine 2 consecutive characters, getting you something non-reconstructible (plus, it might insert invalid-code-point control characters). You can configure `iso-8859-1` (check the lib it's actually windows-1252, but this should be no problem). The official code map of `iso-8859-1` does not specify all required mappings, but there are some code points defined in the decoder source code it seems. Now you will have some invalid characters. Next, one can use the [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) or [ruby](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html) filter to fix wrong code points. For example in CP865 the `ø` character has the code map ID 0x9B (155), and code point 00F8 (unicode). In the windows 152 mapping the code map ID 0x9B has the unicode code point 203a. That is, we can add a mapping of `u+203a => u+00F8` to our translation table and this way create the correct utf-8 encoded text.

---

<div class="post-metadata">

**Author:** ![eikeskog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eikeskog/32/22481_2.png) [@eikeskog](https://discuss.elastic.co/u/eikeskog)\
**Post date:** [October 16, 2018, 11:22am UTC](https://discuss.elastic.co/t/cp865-encoded-logs/152238/3 "2018-10-16T11:22:06Z")

</div>

Thanks for reply.

I actually solved this by setting encoding in filebeat to cp866 and then just replace the affected characters. Ex: gsub =\> ["message", "Ы", "ø"]

I tried other encodings in filebeat, but they rendered all unknown characters with same code.

I will open a github issue concering this.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 16, 2018, 9:06pm UTC](https://discuss.elastic.co/t/cp865-encoded-logs/152238/4 "2018-10-16T21:06:40Z")

</div>

> I actually solved this by setting encoding in filebeat to cp866 and then just replace the affected characters. Ex: gsub =\> ["message", "Ы", "ø"]

Didn't expect cp866 to be close enough. But great you found a workaround.

> I will open a github issue concering this.

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 13, 2018, 9:06pm UTC](https://discuss.elastic.co/t/cp865-encoded-logs/152238/5 "2018-11-13T21:06:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
