# Dealing with invalid json

**URL:** <https://discuss.elastic.co/t/dealing-with-invalid-json/288179>\
**Category:** Logstash\
**Created:** [November 2, 2021, 1:09am UTC](https://discuss.elastic.co/t/dealing-with-invalid-json/288179 "2021-11-02T01:09:36Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![caseydm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/caseydm/32/26771_2.png) [@caseydm](https://discuss.elastic.co/u/caseydm)\
**Post date:** [November 2, 2021, 1:09am UTC](https://discuss.elastic.co/t/dealing-with-invalid-json/288179/1 "2021-11-02T01:09:36Z")

</div>

I'm trying to import some json data that is in a column in redshift. Some of the records have a field that includes invalid json escape sequences, such as this:

```auto
"work_title": "The Discrete and Semi-continuous Fr\'echet Distance with Shortcuts via Approximate Distance Counting and Selection Techniques"

"work_title": "On the \(\partial\overline{\partial}\)-Lemma and Bott-Chern cohomology"

```

I can remove the first one with logstash using this:

```auto
input {
    jdbc {

    }
}

filter {
      mutate {
        gsub => [
          "json_elastic", "\\'", "'"
        ]
      }
      json {
        source => "json_elastic"
      }
      mutate {
        remove_field => ["json_elastic"]
      }
}

output {
     stdout { }
}

```

But is there a way I can expand this to remove the other '/'? I tried this but I get a configuration error:

```auto
mutate {
        gsub => [
          "json_elastic", "\\", ""
        ]
      }

```

Or is there a way to not parse json within that field and simply get the text?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 2, 2021, 2:35am UTC](https://discuss.elastic.co/t/dealing-with-invalid-json/288179/2 "2021-11-02T02:35:03Z")

</div>

The logstash configuration compiler will always interpret a backslash before the end of a double quoted string as escaping the double quote.

The standard trick is to use a single occurrence of a character group with a single member, which is equivalent to the single character in the group: `"[\\]"`

---

<div class="post-metadata">

**Author:** ![caseydm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/caseydm/32/26771_2.png) [@caseydm](https://discuss.elastic.co/u/caseydm)\
**Post date:** [November 2, 2021, 2:28pm UTC](https://discuss.elastic.co/t/dealing-with-invalid-json/288179/3 "2021-11-02T14:28:34Z")

</div>

Awesome, thank you!

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [November 2, 2021, 3:09pm UTC](https://discuss.elastic.co/t/dealing-with-invalid-json/288179/4 "2021-11-02T15:09:47Z")

</div>

This should be added in the documentation, i think a lot of people are struggling with the use of \ to match things.

> [@Badger](#):
>
> "[\]"

I see you around alot i was wondering if there is something to be done to help troubleshooting logstash common problems ( in the documentation )

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 2, 2021, 4:50pm UTC](https://discuss.elastic.co/t/dealing-with-invalid-json/288179/5 "2021-11-02T16:50:16Z")

</div>

I do not know how to get the documentation updated. There are a boatload of small issues I would like to see fixed.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [November 4, 2021, 10:45am UTC](https://discuss.elastic.co/t/dealing-with-invalid-json/288179/6 "2021-11-04T10:45:28Z")

</div>

I think there is a way to update trough [GitHub - elastic/logstash-docs: GENERATED REPOSITORY. DO NOT EDIT. - Documentation repository for Logstash static asciidoc and generated plugin asciidoc.](https://github.com/elastic/logstash-docs/)

I do not know if the pull requests are accepted tho

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 5, 2021, 6:01pm UTC](https://discuss.elastic.co/t/dealing-with-invalid-json/288179/7 "2021-11-05T18:01:32Z")

</div>

[This](https://github.com/logstash-plugins/logstash-filter-mutate/pull/161) is an example of PR that modifies documentation. Like you, I don't know if PRs are accepted from random folk like me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2021, 6:01pm UTC](https://discuss.elastic.co/t/dealing-with-invalid-json/288179/8 "2021-12-03T18:01:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
