# How to escape sprintf (to compare against an uninterpolated value)

**URL:** <https://discuss.elastic.co/t/how-to-escape-sprintf-to-compare-against-an-uninterpolated-value/262581>\
**Category:** Logstash\
**Created:** [January 29, 2021, 2:07am UTC](https://discuss.elastic.co/t/how-to-escape-sprintf-to-compare-against-an-uninterpolated-value/262581 "2021-01-29T02:07:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cknz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cknz/32/9640_2.png) [@cknz](https://discuss.elastic.co/u/cknz)\
**Post date:** [January 29, 2021, 2:07am UTC](https://discuss.elastic.co/t/how-to-escape-sprintf-to-compare-against-an-uninterpolated-value/262581/1 "2021-01-29T02:07:06Z")

</div>

Hi all, I'm on Elastic 7.10.2, and I noticed a problem with my processing. Some incoming data has tried to set a field using a sprintf string, but the sprintf expression did not result in a replacement, so I'm left with a field that contains an uninterpolated string. This is resulting in Elasticsearch complaining because there is no pipeline with a name of (literally) `%{[@metadata][pipeline]}`

(I should point out that this is not a standard Elastic deployment, so please just take it as given that normally there would normally be a `[@metadata][pipeline]`, but some beats (in this case Journalbeat) doesn't set one, which exposed an issue from earlier in my processing.

I'm trying to create a filter to clean up such cases, but to do that I need to compare something with `${[@metadata][pipeline]}` (there are some other examples too). Problem is, I can't seem to escape this so I get a literal sequence of '$' '{' ...

I'm going to fix this properly in my upstream processing, but it seems like something that would useful to know how to do.

Any clues?

Things I've tried:

- `\%`
- `%%`
- single quotes

None appear to have worked, and I do have config.support\_escapes set to true.

I do have a regular expression of `=~ /^%/` that works, but I don't think `=~ /%{/` worked. Would be nice to have something faster than a regex for such a simple thing.

Cheers,  
Cameron

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 29, 2021, 2:20am UTC](https://discuss.elastic.co/t/how-to-escape-sprintf-to-compare-against-an-uninterpolated-value/262581/2 "2021-01-29T02:20:13Z")

</div>

I cannot test it right now, but I think a prune filter should be able to do this. The [default value](https://www.elastic.co/guide/en/logstash/current/plugins-filters-prune.html#plugins-filters-prune-blacklist_names) of blacklist\_names is to remove failed sprintf references. It should be simple to do the same for blacklist\_values,

---

<div class="post-metadata">

**Author:** ![cknz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cknz/32/9640_2.png) [@cknz](https://discuss.elastic.co/u/cknz)\
**Post date:** [January 29, 2021, 3:59am UTC](https://discuss.elastic.co/t/how-to-escape-sprintf-to-compare-against-an-uninterpolated-value/262581/3 "2021-01-29T03:59:43Z")

</div>

I knew there was a reason I like prunes, thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2021, 4:00am UTC](https://discuss.elastic.co/t/how-to-escape-sprintf-to-compare-against-an-uninterpolated-value/262581/4 "2021-02-26T04:00:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
