# Gsub for numbers?

**URL:** <https://discuss.elastic.co/t/gsub-for-numbers/27436>\
**Category:** Logstash\
**Created:** [August 14, 2015, 10:23pm UTC](https://discuss.elastic.co/t/gsub-for-numbers/27436 "2015-08-14T22:23:58Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jclose](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jclose](https://discuss.elastic.co/u/jclose)\
**Post date:** [August 14, 2015, 10:23pm UTC](https://discuss.elastic.co/t/gsub-for-numbers/27436/1 "2015-08-14T22:23:58Z")

</div>

This is a take on a previous topic I posted.

I have values coming across the wire that are meant to go into integer/double/float... values in Elastic, but they are coming cross as string values.

Within logstash, I need to convert these values to null. I can do this with gsub for strings. Is there another way to do with for integers/doubles...?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 15, 2015, 8:22am UTC](https://discuss.elastic.co/t/gsub-for-numbers/27436/2 "2015-08-15T08:22:06Z")

</div>

Not sure exactly what you mean. If your fields indeed are numbers, why would you need to turn them into null? And if they're strings, why doesn't the gsub option work? Perhaps you can give an example or two of input message and the expected output.

---

<div class="post-metadata">

**Author:** ![jclose](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jclose](https://discuss.elastic.co/u/jclose)\
**Post date:** [August 15, 2015, 2:05pm UTC](https://discuss.elastic.co/t/gsub-for-numbers/27436/3 "2015-08-15T14:05:10Z")

</div>

So the issue comes when the fields are numbers, but the data has become corrupted, which happens. If I try to forward the mistyped data to Elastic, I get the dreaded Error 400, which pukes into my log files (and can quickly fill up the drive on my logstash shipper).

I need logstash to normalize the data before it goes to Elastic. I am using templates in Elastic, so it is expecting specific data sites.

Say I have a field that is sent to logstash that is meant to be a number (i.e. {"my\_int" =\> "32" }), but it ends up being bad data (i.e. {"my\_int" =\> "[]"}). I can use grok/regex to find the data in the data stream, but there's nothing that lets me normalize data that may be bad (from a number standpoint).

I need something in logstash to ensure that I send {"my\_int" =\> null} so that Elastic doesn't throw a fit.

Right now, I can use gsub for strings, but don't have anything for numbers.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 16, 2015, 3:10pm UTC](https://discuss.elastic.co/t/gsub-for-numbers/27436/4 "2015-08-16T15:10:10Z")

</div>

Again, an example would help.

Regexp conditionals should work fine:

```
if [message] !~ /^[0-9]+$/ {
  ...
}

```

Or, tighten your grok expression to only match numbers and add the fields with any value you like if there's missing.

I don't know what your gsub looks like so I don't understand why it doesn't work with numbers.

---

<div class="post-metadata">

**Author:** ![Joshua\_Rich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_rich/32/44953_2.png) [@Joshua\_Rich](https://discuss.elastic.co/u/Joshua_Rich)\
**Post date:** [August 17, 2015, 6:06am UTC](https://discuss.elastic.co/t/gsub-for-numbers/27436/5 "2015-08-17T06:06:01Z")

</div>

Why do need to store the field at all for the document where it is corrupted? Couldn't you just use a _remove\_field_ parameter and drop the field altogether?

---

<div class="post-metadata">

**Author:** ![jclose](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jclose](https://discuss.elastic.co/u/jclose)\
**Post date:** [August 17, 2015, 4:13pm UTC](https://discuss.elastic.co/t/gsub-for-numbers/27436/6 "2015-08-17T16:13:09Z")

</div>

So how do I do a conditional remove\_field? I only want to remove the field if it meets a certain condition.

---

<div class="post-metadata">

**Author:** ![jclose](https://avatars.discourse-cdn.com/v4/letter/j/df705f/32.png) [@jclose](https://discuss.elastic.co/u/jclose)\
**Post date:** [August 17, 2015, 4:27pm UTC](https://discuss.elastic.co/t/gsub-for-numbers/27436/7 "2015-08-17T16:27:47Z")

</div>

So, for an example, I have a mutate like the following

```
mutate {
     gsub => ["my_int_value", "(-|\[\])", "null" ]
}

```

This is not working. I am still getting "-" values in the fields getting sent to Elastic, instead of null.

What happens if I do tighten the grok, and now the message coming in does not meet the exact match? Does it throw out the whole message? I just want to throw out single bad fields.

---

<div class="post-metadata">

**Author:** ![Joshua\_Rich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_rich/32/44953_2.png) [@Joshua\_Rich](https://discuss.elastic.co/u/Joshua_Rich)\
**Post date:** [August 18, 2015, 12:14am UTC](https://discuss.elastic.co/t/gsub-for-numbers/27436/8 "2015-08-18T00:14:22Z")

</div>

If you've extracted the field with a `grok` filter, you can just use a logstash conditional to remove it with a `mutate` filter:

```auto
if [field] !~ /^[0-9]+$/ {
  mutate {
    remove_field => ["field"]
  }
}

```

Just put something like that after the grok that extracts/creates that field.

For a grok that doesn't match, the message will be tagged with `_grokparsefailure`. You can process those messages later in the Logstash pipeline if you want.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:31am UTC](https://discuss.elastic.co/t/gsub-for-numbers/27436/9 "2017-07-06T05:31:41Z")

</div>


