# How to gsub \\ in json message

**URL:** <https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713>\
**Category:** Logstash\
**Created:** [June 13, 2019, 5:59pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713 "2019-06-13T17:59:57Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![az123](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@az123](https://discuss.elastic.co/u/az123)\
**Post date:** [June 13, 2019, 5:59pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/1 "2019-06-13T17:59:57Z")

</div>

I have a message below that is failing due to jsonparse error. If I remove all the \ (backslashes) from the message in text editor and check in json parser, it parsed it properly. Now, to get rid of the \ in the json message filed, I tried the mutate + gsub as below (from the official docs) with [\] option which is not working! Need some help with this:

config file:

```auto
filter {
    mutate {
      gsub => ["message", "[\\]", "" ] # << 2 backslashes
}
}

```

```auto
       [0] "_jsonparsefailure"
    ],
        "message" => [
        [0] "{\"node_id_str\":\"xxxx\",\"subscription_id_str\":\"Sub2\",\"encoding_path\":\"Cisco-IOS-XR-shellutil-oper:system-time/uptime\",\"collection_id\":\"151649\",\"collection_start_time\":\"1560440022382\",\"msg_timestamp\":\"1560440022396\",\"data_json\":[{\"timestamp\":\"1560440022394\",\"keys\":[],\"content\":{\"host-name\":\"xxxx\",\"uptime\":6117928}}],\"collection_end_time\":\"1560440022396\"}",

```

So, how do I get rid of the \ in this message? Interestingly, if I try to match it and replace with some char B, it does it next to the \ so not sure what this is matching....

```auto
filter {
   mutate {
     gsub => ["message", "[\\]", "B" ] # << 2 back slashes
 }
}

```

```auto
      "message" => [
        [0] "{B\"node_id_strB\":B\"xxxx-IE1B\",B\"subscription_id_strB\":B\"Sub2B\",B\"encoding_pathB\":B\"Cisco-IOS-XR-shellutil-oper:system-time/uptimeB\",B\"collection_idB\":B\"151843B\",B\"collection_start_timeB\":B\"1560447583109B\",B\"msg_timestampB\":B\"1560447583123B\",B\"data_jsonB\":[{B\"timestampB\":B\"1560447583120B\",B\"keysB\":[],B\"contentB\":{B\"host-nameB\":B\"xxxx-IE1B\",B\"uptimeB\":6125489}}],B\"collection_end_timeB\":B\"1560447583123B\"}",
        [1] "{B\"node_id_strB\":B\"xxxx-IE1B\",B\"subscription_id_strB\":B\"Sub2B\",B\"encoding_pathB\":B\"Cisco-IOS-XR-shellutil-oper:system-time/uptimeB\",B\"collection_idB\":B\"151844B\",B\"collection_start_timeB\":B\"1560447613123B\",B\"msg_timestampB\":B\"1560447613136B\",B\"data_jsonB\":[{B\"timestampB\":B\"1560447613132B\",B\"keysB\":[],B\"contentB\":{B\"host-nameB\":B\"xxxx-IE1B\",B\"uptimeB\":6125519}}],B\"collection_end_timeB\":B\"1560447613136B\"}"

```

_[EDIT: added code-fences around code blocks to increase readability -- @yaauie]_

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 13, 2019, 6:28pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/2 "2019-06-13T18:28:31Z")

</div>

> [@az123](#):
>
> "message" =\> [[0] "{"node\_id\_str":"xxxx","subscription\_id\_str":"Sub2","encoding\_path":"Cisco-IOS-XR-shellutil-oper:system-time/uptime","collection\_id":"151649","collection\_start\_time":"1560440022382","msg\_timestamp":"1560440022396","data\_json":[{"timestamp":"1560440022394","keys":,"content":{"host-name":"xxxx","uptime":6117928}}],"collection\_end\_time":"1560440022396"}",

If that is from rubydebug your message does not contain backslash, it is just rubydebug escaping the double quotes. Not sure how your replacement with B could occur in that case.

---

<div class="post-metadata">

**Author:** ![az123](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@az123](https://discuss.elastic.co/u/az123)\
**Post date:** [June 13, 2019, 7:31pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/3 "2019-06-13T19:31:37Z")

</div>

:-). If that is from ruby debug output plugin, why does logstash fail to parse the json?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 13, 2019, 8:24pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/4 "2019-06-13T20:24:04Z")

</div>

What does the json filter configuration look like?

---

<div class="post-metadata">

**Author:** ![az123](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@az123](https://discuss.elastic.co/u/az123)\
**Post date:** [June 13, 2019, 8:52pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/5 "2019-06-13T20:52:09Z")

</div>

filter {  
mutate {  
split =\> ["message", " "]  
}  
}

filter {  
mutate {  
gsub =\> ["message", '\"', '"']  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 13, 2019, 10:00pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/6 "2019-06-13T22:00:40Z")

</div>

Do you not have a json filter configured? logstash is not going to parse the JSON unless you tell it to.

---

<div class="post-metadata">

**Author:** ![az123](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@az123](https://discuss.elastic.co/u/az123)\
**Post date:** [June 14, 2019, 12:47pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/7 "2019-06-14T12:47:26Z")

</div>

I have tried codec json and json\_lines hoping that it will parse the incoming lines as json. I even added json filter to the end of the config before output but no luck parsing the message to json format. This is what I see when I run logstash:

[WARN] 2019-06-14 12:38:45.267 [[main]\>worker1] json - Error parsing json {:source=\>"message", :raw=\>["{"node\_id\_str":"xxxx","subscription\_id\_str":"Sub2","encoding\_path":"Cisco-IOS-XR-shellutil-oper:system-time/uptime","collection\_id":"152429","collection\_start\_time":"1560515908973","msg\_timestamp":"1560515908990","data\_json":[{"timestamp":"1560515908987","keys":,"content":{"host-name":"xxxx","uptime":6193815}}],"collection\_end\_time":"1560515908990"}"], :exception=\>java.lang.ClassCastException: org.jruby.RubyArray cannot be cast to org.jruby.RubyIO}  
[WARN] 2019-06-14 12:38:45.272 [[main]\>worker1] json - Error parsing json {:source=\>"message", :raw=\>["{"node\_id\_str":"xxxx","subscription\_id\_str":"Sub2","encoding\_path":"Cisco-IOS-XR-shellutil-oper:system-time/uptime","collection\_id":"152429","collection\_start\_time":"1560515908973","msg\_timestamp":"1560515908990","data\_json":[{"timestamp":"1560515908987","keys":,"content":{"host-name":"xxxx","uptime":6193815}}],"collection\_end\_time":"1560515908990"}"], :exception=\>java.lang.ClassCastException: org.jruby.RubyArray cannot be cast to org.jruby.RubyIO}  
/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/awesome\_print-1.7.0/lib/awesome\_print/formatters/base\_formatter.rb:31: warning: constant ::Fixnum is deprecated  
{  
"tags" =\> [  
[0] "\_jsonparsefailure"  
],  
"port" =\> 48700,  
"@timestamp" =\> 2019-06-14T12:38:44.988Z,  
"host" =\> "[xxxx-v0.xxxx.com](http://xxxx-v0.xxxx.com)",  
"@version" =\> "1",  
"message" =\> [  
[0] "{"node\_id\_str":"xxxx","subscription\_id\_str":"Sub2","encoding\_path":"Cisco-IOS-XR-shellutil-oper:system-time/uptime","collection\_id":"152429","collection\_start\_time":"1560515908973","msg\_timestamp":"1560515908990","data\_json":[{"timestamp":"1560515908987","keys":,"content":{"host-name":"xxxx","uptime":6193815}}],"collection\_end\_time":"1560515908990"}"  
],  
"type" =\> "jsonotcp"  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 14, 2019, 1:21pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/8 "2019-06-14T13:21:06Z")

</div>

How did you configure the json filter?

---

<div class="post-metadata">

**Author:** ![az123](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@az123](https://discuss.elastic.co/u/az123)\
**Post date:** [June 14, 2019, 1:34pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/9 "2019-06-14T13:34:48Z")

</div>

filter {  
json {  
source =\> "message"  
target =\> "jsonmessage"  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 14, 2019, 4:15pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/10 "2019-06-14T16:15:37Z")

</div>

You used a mutate+split filter to convert message to an array, so that should be

```
json {
    source => "[message][0]"
    target => "jsonmessage"
}
```

---

<div class="post-metadata">

**Author:** ![az123](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@az123](https://discuss.elastic.co/u/az123)\
**Post date:** [June 14, 2019, 5:03pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/11 "2019-06-14T17:03:46Z")

</div>

That worked for the first element! How do I make it parse every element in the array?

{  
"tags" =\> [  
[0] "\_jsonparsefailure"  
],  
"jsonmessage" =\> {  
"collection\_end\_time" =\> "1560531678180",  
"node\_id\_str" =\> "xxxx",  
"collection\_id" =\> "152579",  
"encoding\_path" =\> "Cisco-IOS-XR-shellutil-oper:system-time/uptime",  
"subscription\_id\_str" =\> "Sub2",  
"collection\_start\_time" =\> "1560531678163",  
"msg\_timestamp" =\> "1560531678180",  
"data\_json" =\> [  
[0] {  
"timestamp" =\> "1560531678176",  
"content" =\> {  
"host-name" =\> "xxxx",  
"uptime" =\> 6209584  
},  
"keys" =\>   
}  
]  
},  
"@timestamp" =\> 2019-06-14T17:01:25.510Z,  
"@version" =\> "1",  
"port" =\> 34850,  
"message" =\> [  
[0] "{"node\_id\_str":"xxxx","subscription\_id\_str":"Sub2","encoding\_path":"Cisco-IOS-XR-shellutil-oper:system-time/uptime","collection\_id":"152579","collection\_start\_time":"1560531678163","msg\_timestamp":"1560531678180","data\_json":[{"timestamp":"1560531678176","keys":,"content":{"host-name":"xxxx","uptime":6209584}}],"collection\_end\_time":"1560531678180"}"  
],  
"host" =\> "[xxxx-v0.xxxx.com](http://xxxx-v0.xxxx.com)",  
"type" =\> "jsonotcp"  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 14, 2019, 5:56pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/12 "2019-06-14T17:56:28Z")

</div>

> [@az123](#):
>
> That worked for the first element! How do I make it parse every element in the array?

I think you would have to use ruby for that.

---

<div class="post-metadata">

**Author:** ![az123](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@az123](https://discuss.elastic.co/u/az123)\
**Post date:** [June 17, 2019, 1:59pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/13 "2019-06-17T13:59:57Z")

</div>

Can you share the code to do so?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 15, 2019, 2:00pm UTC](https://discuss.elastic.co/t/how-to-gsub-in-json-message/185713/14 "2019-07-15T14:00:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
