# Gsub replacing \\\\n with \\n

**URL:** <https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517>\
**Category:** Logstash\
**Created:** [July 18, 2018, 10:56am UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517 "2018-07-18T10:56:50Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![saramali](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@saramali](https://discuss.elastic.co/u/saramali)\
**Post date:** [July 18, 2018, 10:56am UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517/1 "2018-07-18T10:56:50Z")

</div>

I want to replace '\\n' with '\n'

i am using the gsub method but cannot replace

ruby  
{

code =\> "@mystring=event.get('stockLines');  
@mystring=@mystring.gsub('\\n', '\n');"

}

---

<div class="post-metadata">

**Author:** ![saramali](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@saramali](https://discuss.elastic.co/u/saramali)\
**Post date:** [July 18, 2018, 12:02pm UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517/2 "2018-07-18T12:02:58Z")

</div>

@magnusbaeck

---

<div class="post-metadata">

**Author:** ![AurelienG](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@AurelienG](https://discuss.elastic.co/u/AurelienG)\
**Post date:** [July 18, 2018, 2:18pm UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517/3 "2018-07-18T14:18:52Z")

</div>

I'm not sure but I think you should use gsub inside a mutate filter instead of trying to write some ruby code. See [https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-gsub](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-gsub)  
Anyway, I think the problem is with the double backslash: the first backslash is actually used to escape the second backslash so you lack one backslash. And in the result you expect "\n", you also have to escape that backslash, for it to become literal.  
I would try something like:

```auto
filter {
  mutate {
    gsub => [
      "stockLines", "\\\\n", "\\n",
    ]
  }
}

```

If it doesn't work, please tell us what you've tried and what the result was.

Edit: I also found this, if you really prefer using Ruby: [https://www.linuxtopia.org/online\_books/programming\_books/ruby\_tutorial/Ruby\_Standard\_Types\_Backslash\_Sequences\_in\_the\_Substitution.html](https://www.linuxtopia.org/online_books/programming_books/ruby_tutorial/Ruby_Standard_Types_Backslash_Sequences_in_the_Substitution.html)

---

<div class="post-metadata">

**Author:** ![saramali](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@saramali](https://discuss.elastic.co/u/saramali)\
**Post date:** [July 18, 2018, 2:49pm UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517/4 "2018-07-18T14:49:30Z")

</div>

Thanks for writing.  
I tried using mutate as you suggested. But still the issue is there, I can't seem to remove the \\n from my log.

ruby  
{  
code =\> "@stockLines = @stockLines.to\_s + event.get('stockInformation') + '\n';  
if event.get('stockInformation') =~ /Time taken for Variance Price Calculations/  
event.set('stockLog', @stockLines);  
event.set('prev\_stock\_id', @@map['document\_id' + @@map['currentStockNumber']]);  
@stockLines='';  
end"  
}

```
mutate 
{
gsub => [
  "stockLog", "\\\\n", "\\n"
]
}
```

---

<div class="post-metadata">

**Author:** ![tgaudin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgaudin/32/32583_2.png) [@tgaudin](https://discuss.elastic.co/u/tgaudin)\
**Post date:** [July 18, 2018, 2:55pm UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517/5 "2018-07-18T14:55:22Z")

</div>

You can take a look at this topic, I had a similar issue with backslashes and the workaround is a bit ugly [Parse nested key-values](https://discuss.elastic.co/t/parse-nested-key-values/139771/9)

---

<div class="post-metadata">

**Author:** ![AurelienG](https://avatars.discourse-cdn.com/v4/letter/a/76d3ee/32.png) [@AurelienG](https://discuss.elastic.co/u/AurelienG)\
**Post date:** [July 18, 2018, 3:00pm UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517/6 "2018-07-18T15:00:05Z")

</div>

Your 'stockInformation' field already ends with a backslash, right? I guess that's why you have \\n in the end. Maybe you can try to remove that backslash first with:

```auto
mutate {
   gsub => [
     "stockInformation", "[\\]", " "
   ]
}

```

And then add the "\n" to your stockLog.

---

<div class="post-metadata">

**Author:** ![saramali](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@saramali](https://discuss.elastic.co/u/saramali)\
**Post date:** [July 18, 2018, 3:36pm UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517/7 "2018-07-18T15:36:14Z")

</div>

Well I want to add a new line character at the end of each stockLine.

Therefore I concatenate it with the newline character.  
@stockLines = @stockLines.to\_s + event.get('stockInformation') + '\n'

But it concatenates \\n instead of \n. Therefore I was trying if I could substitute \\n with \n. I can't seem to do that anyway. I just want to concatenate a newline character at the end. Somehow \n is converted into \\n

---

<div class="post-metadata">

**Author:** ![tgaudin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgaudin/32/32583_2.png) [@tgaudin](https://discuss.elastic.co/u/tgaudin)\
**Post date:** [July 18, 2018, 3:50pm UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517/8 "2018-07-18T15:50:02Z")

</div>

In Ruby if you write a string with single quotes it will escape any `\n`.  
You need to concatenate with `"\n"`, eg:  
`@stockLines = @stockLines.to_s + event.get('stockInformation') + "\n"`

---

<div class="post-metadata">

**Author:** ![saramali](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@saramali](https://discuss.elastic.co/u/saramali)\
**Post date:** [July 18, 2018, 4:06pm UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517/9 "2018-07-18T16:06:33Z")

</div>

How can I do that in double qoutes, assuming the

code =\> tag opens with a double qoute too.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 18, 2018, 4:11pm UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517/10 "2018-07-18T16:11:24Z")

</div>

Use single quotes

---

<div class="post-metadata">

**Author:** ![tgaudin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgaudin/32/32583_2.png) [@tgaudin](https://discuss.elastic.co/u/tgaudin)\
**Post date:** [July 18, 2018, 4:11pm UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517/11 "2018-07-18T16:11:27Z")

</div>

You could either change the `code => "<ruby code>"` to use single quotes, and change all quotes in your ruby code to double quotes (`code => '@stockLines = @stockLines.to_s + event.get("stockInformation") + "\n"; <other code>'`).  
Or you could extract the ruby script to a separate file, and link to it with `path => "/path/to/script.rb"`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2018, 4:11pm UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517/12 "2018-08-15T16:11:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
