# Elasticsearch Ingest node gsub processor replace character

**URL:** <https://discuss.elastic.co/t/elasticsearch-ingest-node-gsub-processor-replace-character/115817>\
**Category:** Elasticsearch\
**Created:** [January 17, 2018, 3:23am UTC](https://discuss.elastic.co/t/elasticsearch-ingest-node-gsub-processor-replace-character/115817 "2018-01-17T03:23:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![anson\_ch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anson_ch/32/26647_2.png) [@anson\_ch](https://discuss.elastic.co/u/anson_ch)\
**Post date:** [January 17, 2018, 3:23am UTC](https://discuss.elastic.co/t/elasticsearch-ingest-node-gsub-processor-replace-character/115817/1 "2018-01-17T03:23:56Z")

</div>

I am trying to use the gsub processor to replace characters such as `"` to `\"`

```auto
curl -XPOST 'localhost:9200/_ingest/pipeline/_simulate?pretty' -H 'Content-Type: application/json' -d'
{
  "pipeline": {
  "description" : "parse multiple patterns",
  "processors": [
    {
	  "gsub": {
        "field": "message",
        "pattern": """,
        "replacement": "\""
      }
    }
  ]
},
"docs":[
  {
    "_source": {
      "message": "I have a "pen", you know!"
    }
  }
  ]
}
'

```

but has error

```auto
 "error" : {
        "reason" : "Failed to parse content to map"
      }
    ],
    "type" : "parse_exception",
    "reason" : "Failed to parse content to map",
    "caused_by" : {
      "type" : "json_parse_exception",
      "reason" : "Unexpected character ('\"' (code 34)): was expecting comma to separate Object entries\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@7b179814; line: 9, column: 23]"
    }
  },
  "status" : 400
}

```

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [January 17, 2018, 3:29am UTC](https://discuss.elastic.co/t/elasticsearch-ingest-node-gsub-processor-replace-character/115817/2 "2018-01-17T03:29:53Z")

</div>

> [@anson\_ch](#):
>
> "I have a "pen", you know!"

The problem is that what you give in the source above is not valid JSON. You're supposed to encode the double quotes before it reaches the pipeline.

---

<div class="post-metadata">

**Author:** ![anson\_ch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anson_ch/32/26647_2.png) [@anson\_ch](https://discuss.elastic.co/u/anson_ch)\
**Post date:** [January 17, 2018, 8:40am UTC](https://discuss.elastic.co/t/elasticsearch-ingest-node-gsub-processor-replace-character/115817/3 "2018-01-17T08:40:05Z")

</div>

my log is shipped by filebeat, the original log is just like this`192.168.1.2 - - [10/Jul/2015:15:51:09 +0800] "GET /ubuntu.iso HTTP/1.0"`, i try to parse it in someways with grok processor, but cannot process double quotes,

```auto
curl -XPOST 'localhost:9200/_ingest/pipeline/_simulate?pretty' -H 'Content-Type: application/json' -d'
{
  "pipeline": {
  "description" : "parse multiple patterns",
  "processors": [
    {
      "grok": {
        "field": "message",
        "patterns": ["%{IP:ip}\\s-\\s-\\s\\[%{TIME:time}\\s\\S+\\]\\s\"%{REQUEST:request}\"\\s\\d+"],
		"pattern_definitions" : {
          "IP" : "(\\S+)",
		  "TIME": "(\\S+)",
		  "REQUEST": "\\w+"
        }
      }
    }
  ]
},
"docs":[
  {
    "_source": {
      "message": "192.168.1.2 - - [10/Jul/2015:15:51:09 +0800] "GET" 168"
    }
  }
  ]
}
'

```

do i need to encode the _message_ in json format with filbeat first,and then send to es?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2018, 8:40am UTC](https://discuss.elastic.co/t/elasticsearch-ingest-node-gsub-processor-replace-character/115817/4 "2018-02-14T08:40:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
