# Filebeat Inserts \\t in place of tabs in Logstash

**URL:** <https://discuss.elastic.co/t/filebeat-inserts-t-in-place-of-tabs-in-logstash/139402>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 10, 2018, 4:53pm UTC](https://discuss.elastic.co/t/filebeat-inserts-t-in-place-of-tabs-in-logstash/139402 "2018-07-10T16:53:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![charan.gandra](https://avatars.discourse-cdn.com/v4/letter/c/a87d85/32.png) [@charan.gandra](https://discuss.elastic.co/u/charan.gandra)\
**Post date:** [July 10, 2018, 4:53pm UTC](https://discuss.elastic.co/t/filebeat-inserts-t-in-place-of-tabs-in-logstash/139402/1 "2018-07-10T16:53:34Z")

</div>

Hi,

Need some help, I am shipping the logs using filebeat to remote Logstash and my log contains tabs in between. Following LS filter was working perfectly until yesterday.

```
kv {
  value_split => "::"
  trim_value => ":"
  field_split => "\\t"
  include_keys => ["HOSTNAME", "HOSTSTATE", "HOSTSTATETYPE"]
}

```

However I tried to modify my filter to include other logs and it's broken now as filebeat is replaceing tab with \t while shipping the logs. I've reverted all my changes to the original filter but still no luck.

Just to be sure it is not filter which is causing the issue I've removed the filter completely, but still getting the same error.

Jul 10 16:49:11 LSSERVER logstash: "message" =\> "DATATYPE::HOSTPERFDATA\tTIMET::1531241345\tHOSTNAME::BEATSSERVER\tHOSTPERFDATA::\tHOSTCHECKCOMMAND::check-host-alive\tHOSTSTATE::UP\tHOSTSTATETYPE::HARD",

I can rewrite the filter to split the fields on \t but I want to understand what is it causing this issue.

Any help is greately appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 7, 2018, 4:53pm UTC](https://discuss.elastic.co/t/filebeat-inserts-t-in-place-of-tabs-in-logstash/139402/2 "2018-08-07T16:53:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
