# How filebeat handle json string with backslash

**URL:** <https://discuss.elastic.co/t/how-filebeat-handle-json-string-with-backslash/153012>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 18, 2018, 1:50pm UTC](https://discuss.elastic.co/t/how-filebeat-handle-json-string-with-backslash/153012 "2018-10-18T13:50:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![kimown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimown/32/36677_2.png) [@kimown](https://discuss.elastic.co/u/kimown)\
**Post date:** [October 18, 2018, 1:50pm UTC](https://discuss.elastic.co/t/how-filebeat-handle-json-string-with-backslash/153012/1 "2018-10-18T13:50:03Z")

</div>

Hi, I am using `keys_under_root`

[https://www.elastic.co/guide/en/beats/filebeat/5.2/configuration-filebeat-options.html#config-json](https://www.elastic.co/guide/en/beats/filebeat/5.2/configuration-filebeat-options.html#config-json)

I know `{\"text\":\"message with backslash\"}` is not a valid json string, so filebeat treat this message as string, but how can I remove backslash before double quote, does this can be done only in filebeat? should I use logstash?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 18, 2018, 10:02pm UTC](https://discuss.elastic.co/t/how-filebeat-handle-json-string-with-backslash/153012/2 "2018-10-18T22:02:44Z")

</div>

For this I'd use logstash. Is there a chance of the text being escaped with slashes as well? This looks like escaping gone wrong, trying to repair it can be a little tricky if you have embedded escaped text, which must not de-escaped yet.

---

<div class="post-metadata">

**Author:** ![kimown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimown/32/36677_2.png) [@kimown](https://discuss.elastic.co/u/kimown)\
**Post date:** [October 19, 2018, 2:38am UTC](https://discuss.elastic.co/t/how-filebeat-handle-json-string-with-backslash/153012/3 "2018-10-19T02:38:58Z")

</div>

I find a solution about the invalid json string, just wrap string as value of json, the key is random, eg: we can use `requestBody`, so the raw log looks like this: `{"requestBody": "{\"text\":\"message with backslash\"}"}`. In this case, I have a question, can we treat `{\"text\":\"message with backslash\"}` as the root because we don't need the outer.

[https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html#decode-json-example](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html#decode-json-example)

---

<div class="post-metadata">

**Author:** ![kimown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimown/32/36677_2.png) [@kimown](https://discuss.elastic.co/u/kimown)\
**Post date:** [October 19, 2018, 3:21am UTC](https://discuss.elastic.co/t/how-filebeat-handle-json-string-with-backslash/153012/4 "2018-10-19T03:21:34Z")

</div>

updated: delete duplicate comment

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 19, 2018, 12:31pm UTC](https://discuss.elastic.co/t/how-filebeat-handle-json-string-with-backslash/153012/5 "2018-10-19T12:31:46Z")

</div>

See: [decode\_json processor docs](https://www.elastic.co/guide/en/beats/filebeat/current/decode-json-fields.html#decode-json-fields).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2018, 12:31pm UTC](https://discuss.elastic.co/t/how-filebeat-handle-json-string-with-backslash/153012/6 "2018-11-16T12:31:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
