# Filebeat Azure Activity Logs Ingest Pipeline; Error parsing fields with $-characters

**URL:** https://discuss.elastic.co/t/filebeat-azure-activity-logs-ingest-pipeline-error-parsing-fields-with-characters/253571
**Category:** Beats
**Tags:** filebeat
**Created:** [October 28, 2020, 1:58pm UTC](https://discuss.elastic.co/t/filebeat-azure-activity-logs-ingest-pipeline-error-parsing-fields-with-characters/253571 "2020-10-28T13:58:08Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![C0FFEEC0FFEE](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/c0ffeec0ffee/32/75111_2.png) [@C0FFEEC0FFEE](https://discuss.elastic.co/u/C0FFEEC0FFEE)
#### Post date: [October 28, 2020, 1:58pm UTC](https://discuss.elastic.co/t/filebeat-azure-activity-logs-ingest-pipeline-error-parsing-fields-with-characters/253571/1 "2020-10-28T13:58:08Z")

</div>

I'm trying to enhance the filebeat-7.9.3-azure-activitylogs-pipeline to parse the information about vulnerability scans (Azure Security Center / Qualys) into ECS.

I'm stuck with the problem that some of the fields have a $-character in their name.

The error is

```auto
[script_exception] compile error, with { script_stack={ 0="... itionalData?.Cvss?.2?.0?.$type == 'additionalData/ ..." & 1=" ^---- HERE" } & script="ctx.azure.activitylogs.Type == 'Microsoft.Security/assessments/subAssessments' && ctx.azure.activitylogs.Properties?.AdditionalData?.AssessedResourceType == 'ServerVulnerability' && ctx.azure.activitylogs.Properties?.AdditionalData?.Cvss?.2?.0?.$type == 'additionalData/cvss'" & lang="painless" & position={ offset=245 & start=220 & end=270 } }

```

My processor is as follows, if I remove the $ sign (i.e. rename $type to type), the error goes away.

```auto
"set": {
        "if": "ctx.azure.activitylogs.Type == 'Microsoft.Security/assessments/subAssessments' && ctx.azure.activitylogs.Properties?.AdditionalData?.AssessedResourceType == 'ServerVulnerability' && ( ctx.azure.activitylogs.Properties?.AdditionalData?.Cvss?.2?.0?.$type == 'additionalData/cvss' || azure.activitylogs.Properties?.AdditionalData?.Cvss?.3?.0?.$type == 'additionalData/cvss')",
        "field": "vulnerability.classification",
        "value": "cvss"
}

```

Does anybody have an idea how I can avoid this? Escaping the $ with backslashes didn't help. 😕

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 25, 2020, 3:58pm UTC](https://discuss.elastic.co/t/filebeat-azure-activity-logs-ingest-pipeline-error-parsing-fields-with-characters/253571/2 "2020-11-25T15:58:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
