# Gsub replace backslash with forward slash

**URL:** <https://discuss.elastic.co/t/gsub-replace-backslash-with-forward-slash/233322>\
**Category:** Logstash\
**Created:** [May 19, 2020, 12:57pm UTC](https://discuss.elastic.co/t/gsub-replace-backslash-with-forward-slash/233322 "2020-05-19T12:57:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sjivan](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@sjivan](https://discuss.elastic.co/u/sjivan)\
**Post date:** [May 19, 2020, 12:57pm UTC](https://discuss.elastic.co/t/gsub-replace-backslash-with-forward-slash/233322/1 "2020-05-19T12:57:31Z")

</div>

Hi,  
I'm trying to replace a forward slash to back slash using gsub but can't get it to work.

I've tried

```auto
gsub => ["message", "/", "\\"]
```

and

```auto
gsub => ["message", "/", "\"]
```

The above fails with a parse error.

and

```auto
gsub => ["message", "[/]", "[\\]"]
```

does the wrong thing by adding the brackets in the substituted string.

Any pointers would be appreciated.

Thanks,  
Sanjiv

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [May 19, 2020, 5:52pm UTC](https://discuss.elastic.co/t/gsub-replace-backslash-with-forward-slash/233322/2 "2020-05-19T17:52:08Z")

</div>

Hi, you need a very tricky substitution 😲 😀

The only way of achieving it that comes to my mind is to use ruby code directly:

```auto
  ruby{
    code => ' event.set("message", event.get("message").gsub("/", "\\") ) '
  }

```

Be aware that if your output representation escapes special characters (for example Json), you'll see "doubled" backquotes in the result.

I add a link to a message with a related issue to have as reference and another unresolved one that might benefit from this.

> [@Proper RegEx with Mutate\>GSub](https://discuss.elastic.co/t/proper-regex-with-mutate-gsub/229679/2):
>
> Having a backslash at the end of a string requires a trick. Use a character group that just includes backslash... mutate { gsub =\> ["[user][name]", "\w+[\\]{2}", "" ] }

> [@Logstash gsub: how to replace with backslash?](https://discuss.elastic.co/t/logstash-gsub-how-to-replace-with-backslash/58364):
>
> Hi, I have following stuff in a field: "field\_A" =\> "c:\\test\\test.txt" By some conversion the masking backslash became a valid character. How can I get rid of the double backslashes, so that I have only one (or two when masked)? I tried: mutate { gsub =\> ['field\_A', '(\\\\)', '\\'] } but that is not accepted by logstash. If I try to replace to '[\]' then the brackets are also inserted. Any idea? Thanks a lot.

---

<div class="post-metadata">

**Author:** ![sjivan](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@sjivan](https://discuss.elastic.co/u/sjivan)\
**Post date:** [May 19, 2020, 6:11pm UTC](https://discuss.elastic.co/t/gsub-replace-backslash-with-forward-slash/233322/3 "2020-05-19T18:11:55Z")

</div>

That's exactly what I resorted to after many tries. I figured I was doing something wrong as replacing forward slash with backslash is a seemingly simple requirement.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2020, 6:26pm UTC](https://discuss.elastic.co/t/gsub-replace-backslash-with-forward-slash/233322/4 "2020-06-16T18:26:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
