# Find and replace string in \[message\] field

**URL:** <https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319>\
**Category:** Logstash\
**Created:** [August 8, 2017, 5:57pm UTC](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319 "2017-08-08T17:57:12Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![ash007](https://avatars.discourse-cdn.com/v4/letter/a/ccd318/32.png) [@ash007](https://discuss.elastic.co/u/ash007)\
**Post date:** [August 8, 2017, 5:57pm UTC](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319/1 "2017-08-08T17:57:12Z")

</div>

Hi,  
I want to replace a string in my message field. How should i proceed in logstash filter.  
Below is a sample [message] log:  
input to logstash:(before parsing)  
some text in the beginning **Auth: Sec slghltrgj;sjtg;String to replaced;rtfygjhrslfknr;f** some text after  
output from logstash: (after parsing)  
some text in the beginning \*\*Auth: Sec \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* some text after

Can anyone provide some ideas on how i can do the above parsing in logstash?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 8, 2017, 8:33pm UTC](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319/2 "2017-08-08T20:33:05Z")

</div>

Use a mutate filter and its gsub option.

---

<div class="post-metadata">

**Author:** ![ash007](https://avatars.discourse-cdn.com/v4/letter/a/ccd318/32.png) [@ash007](https://discuss.elastic.co/u/ash007)\
**Post date:** [August 9, 2017, 2:58pm UTC](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319/3 "2017-08-09T14:58:37Z")

</div>

Thanks @magnusbaeck  
Is there a way i can do the following using logstash filters:  
I have an ID stored in a field example id: 123456789.  
I want to replace first 5 digits with an 'x'. so that id looks like, id:xxxxx6789.  
How can i do this in logstash filters?

Thanks.

---

<div class="post-metadata">

**Author:** ![ash007](https://avatars.discourse-cdn.com/v4/letter/a/ccd318/32.png) [@ash007](https://discuss.elastic.co/u/ash007)\
**Post date:** [August 16, 2017, 3:46pm UTC](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319/4 "2017-08-16T15:46:11Z")

</div>

@magnusbaeck Is there a way we can perform a count operation in if condition in logstash filter.  
For example:  
I am trying to check the occurrence of "text" in my [message] field.  
something like this,  
filter{  
if count("text")[message] \>1 {  
"do something"  
}  
}  
if this is not possible, could you suggest a way to do this kind of operation.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 16, 2017, 7:10pm UTC](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319/5 "2017-08-16T19:10:56Z")

</div>

You'd have to use a ruby filter for this.

---

<div class="post-metadata">

**Author:** ![ash007](https://avatars.discourse-cdn.com/v4/letter/a/ccd318/32.png) [@ash007](https://discuss.elastic.co/u/ash007)\
**Post date:** [August 16, 2017, 7:15pm UTC](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319/6 "2017-08-16T19:15:39Z")

</div>

@magnusbaeck  
Could show a small example on how can i can proceed on this please.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 16, 2017, 7:22pm UTC](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319/7 "2017-08-16T19:22:35Z")

</div>

Sorry, I don't have time to do that. There are plenty of ruby filter examples around and the code itself is pretty normal Ruby code.

---

<div class="post-metadata">

**Author:** ![ash007](https://avatars.discourse-cdn.com/v4/letter/a/ccd318/32.png) [@ash007](https://discuss.elastic.co/u/ash007)\
**Post date:** [August 17, 2017, 6:48pm UTC](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319/8 "2017-08-17T18:48:07Z")

</div>

@magnusbaeck  
ok.  
Could you just help with this?  
event.set('count', event.get('message').count.('text'))

I am getting the below error:  
[ERROR][logstash.filters.ruby] Ruby exception occurred: wrong number of arguments

How can i correct this?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 17, 2017, 7:34pm UTC](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319/9 "2017-08-17T19:34:11Z")

</div>

`count('text')`, not `count.('text')`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2017, 7:34pm UTC](https://discuss.elastic.co/t/find-and-replace-string-in-message-field/96319/10 "2017-09-14T19:34:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
