# Default value escaping

**URL:** <https://discuss.elastic.co/t/default-value-escaping/189362>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 8, 2019, 1:59pm UTC](https://discuss.elastic.co/t/default-value-escaping/189362 "2019-07-08T13:59:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alex\_Zeleznikov1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_zeleznikov1/32/45312_2.png) [@Alex\_Zeleznikov1](https://discuss.elastic.co/u/Alex_Zeleznikov1)\
**Post date:** [July 8, 2019, 1:59pm UTC](https://discuss.elastic.co/t/default-value-escaping/189362/1 "2019-07-08T13:59:01Z")

</div>

How can I escape default values when doing variable substitution?  
for example `multiline.pattern: '${kubernetes.annotations.multiline_pattern:^(0[1-9]|[1-2][0-9]|3[0-1])-(0[1-9]|1[0-2])-[0-9]{4}}'` I need to change the regex pattern but when I add `:` or `` filebeat doesn’t match the event correctly, can I somehow escape chars in the default value?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 9, 2019, 12:30am UTC](https://discuss.elastic.co/t/default-value-escaping/189362/2 "2019-07-09T00:30:20Z")

</div>

Yay, escaping strings ☹

Looking at your regex I think the `}}` is a problem while parsing the configuration. I think you can escape the first `}` using `$}`, like:

```auto
multiline.pattern: '${kubernetes.annotations.multiline_pattern:^(0[1-9]|[1-2][0-9]|3[0-1])-(0[1-9]|1[0-2])-[0-9]{4}}'

```

I think variable expansion was recursive (given there are no loops). This means you should be able to write the sample like this (note: I didn't test this):

```auto
multiline.pattern: '${kubernetes.annotations.multiline_pattern:${patterns.default.timestamp}}'

patterns:
  default.timestamp: '^(0[1-9]|[1-2][0-9]|3[0-1])-(0[1-9]|1[0-2])-[0-9]{4}'

```

What's nice is that this removes the need for escaping.

Being adventures we can try to create 'named' predefined multiline patterns for reuse (Note: I didn't test this):

```auto
multiline.pattern: '${kubernetes.annotations.multiline_pattern:${patterns.multiline.${kubernetes.annotations.multiline_type:default}}}'

patterns.multiline:
  default: ${pattern.multiline.date}
  date: '^(0[1-9]|[1-2][0-9]|3[0-1])-(0[1-9]|1[0-2])-[0-9]{4}'
  other: '...'

  ...

```

Here we are playing with string replacement, but one can actually point to actual objects in the configuration file.

---

<div class="post-metadata">

**Author:** ![Alex\_Zeleznikov1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_zeleznikov1/32/45312_2.png) [@Alex\_Zeleznikov1](https://discuss.elastic.co/u/Alex_Zeleznikov1)\
**Post date:** [August 1, 2019, 10:50am UTC](https://discuss.elastic.co/t/default-value-escaping/189362/3 "2019-08-01T10:50:14Z")

</div>

Thanks steffens, I haven't tried this configuration on Filebeat yet, but would this work with Curator?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2019, 10:50am UTC](https://discuss.elastic.co/t/default-value-escaping/189362/4 "2019-08-29T10:50:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
