# How to handle german Umlauts or anything thats not UTF-8

**URL:** <https://discuss.elastic.co/t/how-to-handle-german-umlauts-or-anything-thats-not-utf-8/25294>\
**Category:** Logstash\
**Created:** [July 10, 2015, 8:02am UTC](https://discuss.elastic.co/t/how-to-handle-german-umlauts-or-anything-thats-not-utf-8/25294 "2015-07-10T08:02:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![roflrox](https://avatars.discourse-cdn.com/v4/letter/r/d2c977/32.png) [@roflrox](https://discuss.elastic.co/u/roflrox)\
**Post date:** [July 10, 2015, 8:02am UTC](https://discuss.elastic.co/t/how-to-handle-german-umlauts-or-anything-thats-not-utf-8/25294/1 "2015-07-10T08:02:46Z")

</div>

Hallo,

i had a little Problem with processing Logmessages that contain some german umlauts.  
But i found a solution how to handle umlauts (or anything which is not UTF-8 encoded)

When you check the logstash.log you might find something like this:

:message=\>"Received an event that has a different character encoding than you configured.", :text=\>"here is your message", :expected\_charset=\>"UTF-8",

Here is my solution:

```

input{
    
    lumberjack{
        port => 5043
         ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
         ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
         codec => plain {charset => "CP1252" } # you can use another but this charset works perfectly for german
    }
}
filter{
    mutate{
        gsub => [
            # replace all german umlauts
            # this is optional, logstash will convert the umlauts to the correct unicode codepoint
            "message", "ä", "ae",
            "message", "ö", "oe",
            "message", "ü", "ue"
            
        ]
    }
...
}

```

Logstash converts the Umlauts to the the correct unicode codepoints. You don't have to replace them, if you don't want to.

If you copy this in your logstash.conf via Windows (e.g. via Notepad++ and and winSCP) and you try to run it on a machine using a unix based OS, logstash might not start and write this message:

:message=\>"Error: The following config files contains non-ascii characters but are not UTF-8 encoded ["/etc/logstash/central.conf"]"

In this case, use vim or nano directly on your unix-machine to insert this.

Kind regards

Rolf

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 10, 2015, 8:10am UTC](https://discuss.elastic.co/t/how-to-handle-german-umlauts-or-anything-thats-not-utf-8/25294/2 "2015-07-10T08:10:24Z")

</div>

Nice solution 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 10, 2015, 8:55am UTC](https://discuss.elastic.co/t/how-to-handle-german-umlauts-or-anything-thats-not-utf-8/25294/3 "2015-07-10T08:55:51Z")

</div>

I don't understand. If you declare a character set for your input plugin that matches the actual input text, won't Logstash do the right thing by reading the characters correctly and converting them to the correct Unicode codepoints?

---

<div class="post-metadata">

**Author:** ![roflrox](https://avatars.discourse-cdn.com/v4/letter/r/d2c977/32.png) [@roflrox](https://discuss.elastic.co/u/roflrox)\
**Post date:** [July 10, 2015, 9:21am UTC](https://discuss.elastic.co/t/how-to-handle-german-umlauts-or-anything-thats-not-utf-8/25294/4 "2015-07-10T09:21:33Z")

</div>

You're right, logstash converts them directly to the unicode codepoints. It isn't necessary to replace the umlauts, if you want to keep them.

I will add this. thanks for your hint

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:35am UTC](https://discuss.elastic.co/t/how-to-handle-german-umlauts-or-anything-thats-not-utf-8/25294/5 "2017-07-06T05:35:02Z")

</div>


