# Help with removing parts of log output

**URL:** <https://discuss.elastic.co/t/help-with-removing-parts-of-log-output/121259>\
**Category:** Logstash\
**Created:** [February 23, 2018, 5:28pm UTC](https://discuss.elastic.co/t/help-with-removing-parts-of-log-output/121259 "2018-02-23T17:28:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Feedy](https://avatars.discourse-cdn.com/v4/letter/f/76d3ee/32.png) [@Feedy](https://discuss.elastic.co/u/Feedy)\
**Post date:** [February 23, 2018, 5:28pm UTC](https://discuss.elastic.co/t/help-with-removing-parts-of-log-output/121259/1 "2018-02-23T17:28:15Z")

</div>

I would like to remove, if possible, the \r\n data and replace with a whitespace from the log file below....  
Log file:  
`Feb 20 13:00:10 172.19.1.181 1 2018-02-20T11:50:23.000Z removed-data-vices.com KES|10.2.4.0 - 00000193 [event@23668 et="00000193" tdn="Application Privilege Control" etdn="Application Privilege Control rule triggered" hdn="ABC-DE-AA-003" hip="10.148.123.22"] Event type: Application Privilege Control rule triggered\r\nApplication\Name: MOM Client Software\r\nApplication\Path: c:\program files\removed_client\\r\nApplication\Process ID: 7928\r\nUser: ABC\nobody (Active user)\r\nComponent: Application Privilege Control\r\nResult\Description: Allowed\r\nResult\Type: Registry access\r\nResult\Name: SystemServices2\r\nResult\Threat level: Low\r\nResult\Precision: Exactly\r\nAction: Create\r\nObject: hklm\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS\r\nObject\Type: Registry key\r\nObject\Path: hklm\SYSTEM\CONTROLSET001\SERVICES\TCPIP\\r\nObject\Name: PARAMETERS\r\nReason: SystemServices2\r\n`

I've tried the mutate filter testing just one named field for testing but not getting expected results:

```auto
mutate {
 gsub => [
   "Type2", "[(\r\n|\r|\n)]", ""
   ]
  }

```

---

<div class="post-metadata">

**Author:** ![Feedy](https://avatars.discourse-cdn.com/v4/letter/f/76d3ee/32.png) [@Feedy](https://discuss.elastic.co/u/Feedy)\
**Post date:** [February 23, 2018, 5:45pm UTC](https://discuss.elastic.co/t/help-with-removing-parts-of-log-output/121259/2 "2018-02-23T17:45:04Z")

</div>

I think I figured out my issue....rewriting grok pattern now to test....

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 23, 2018, 5:53pm UTC](https://discuss.elastic.co/t/help-with-removing-parts-of-log-output/121259/3 "2018-02-23T17:53:57Z")

</div>

On Linux, the following will work, where these are a literal newline and ctrl/M in the string.

```auto
mutate { 
gsub => [ "message", "[
^M]", "" ]
} 

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2018, 5:54pm UTC](https://discuss.elastic.co/t/help-with-removing-parts-of-log-output/121259/4 "2018-03-23T17:54:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
