# Gsub - Replace windows line terminators (\\r\\n) with unix (\\n)

**URL:** <https://discuss.elastic.co/t/gsub-replace-windows-line-terminators-r-n-with-unix-n/277394>\
**Category:** Logstash\
**Created:** [June 30, 2021, 1:45am UTC](https://discuss.elastic.co/t/gsub-replace-windows-line-terminators-r-n-with-unix-n/277394 "2021-06-30T01:45:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![metalshanked](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/metalshanked/32/87159_2.png) [@metalshanked](https://discuss.elastic.co/u/metalshanked)\
**Post date:** [June 30, 2021, 1:45am UTC](https://discuss.elastic.co/t/gsub-replace-windows-line-terminators-r-n-with-unix-n/277394/1 "2021-06-30T01:45:32Z")

</div>

Hi,  
I am trying to format a csv file so that it can be used in the translate filter.  
the csv file has only two columns (comma separated) with windows line ending format (CRLF)  
which somehow causes the translate filter to throw an error --\> "Unquoted fields do not allow \r or \n"

So, i attempted to use gsub to format the file to have Unix (LF) like the below.

```auto
filter {
    mutate {
        gsub => ["message", "\r\n", "\n"]
    }
}

```

However, Although translate does not throw an error anymore, i dont think this is working since when i cat or nano the file...i see the contents in one long line like --\> value1,value2\nvalue3,value4\nvalue5,value6....  
instead of  
value1  
value2  
value3  
value4  
value5  
value6

Also, filters like cidr seem to throw an error saying it could not find valid network called "\n" which furthers the above assumption that it is somehow it is not able to "detect" an actual newline in the file.

I also tried various combinations like  
gsub =\> ["message", "\r\n", "\n"]  
gsub =\> ["message", "\\r\\\n", "\n"]  
etc. but none of them worked

Any assistance would be appreciated

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![metalshanked](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/metalshanked/32/87159_2.png) [@metalshanked](https://discuss.elastic.co/u/metalshanked)\
**Post date:** [June 30, 2021, 2:22am UTC](https://discuss.elastic.co/t/gsub-replace-windows-line-terminators-r-n-with-unix-n/277394/2 "2021-06-30T02:22:16Z")

</div>

Update:  
I think the below is working to replace CRLF with LF

```auto
gsub => ["message", "\r", ""]

```

i did a cat -A myfile.csv and the output is like the below ($ stands for newline/LF i believe in cat -A)

value1,value2$  
value2,value3$  
value4,value5$  
$

However, now i get a different error with translate filter on the file  
exception=\>#\<LogStash::Filters::Dictionary::DictionaryFileError: Translate: no implicit conversion of nil into String when loading dictionary file

---

<div class="post-metadata">

**Author:** ![metalshanked](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/metalshanked/32/87159_2.png) [@metalshanked](https://discuss.elastic.co/u/metalshanked)\
**Post date:** [June 30, 2021, 2:50am UTC](https://discuss.elastic.co/t/gsub-replace-windows-line-terminators-r-n-with-unix-n/277394/3 "2021-06-30T02:50:59Z")

</div>

Update2:  
The extra LF at the end ($) was the issue. I think i got it working with the below

```auto
filter {
    mutate {
        gsub => ["message", "\r", ""]
    }
   mutate {
        strip => "message"
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2021, 2:51am UTC](https://discuss.elastic.co/t/gsub-replace-windows-line-terminators-r-n-with-unix-n/277394/4 "2021-07-28T02:51:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
