# How To remove \\ from the existing log formate

**URL:** <https://discuss.elastic.co/t/how-to-remove-from-the-existing-log-formate/217295>\
**Category:** Logstash\
**Created:** [January 31, 2020, 4:38am UTC](https://discuss.elastic.co/t/how-to-remove-from-the-existing-log-formate/217295 "2020-01-31T04:38:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ozil](https://avatars.discourse-cdn.com/v4/letter/o/a587f6/32.png) [@Ozil](https://discuss.elastic.co/u/Ozil)\
**Post date:** [January 31, 2020, 4:38am UTC](https://discuss.elastic.co/t/how-to-remove-from-the-existing-log-formate/217295/1 "2020-01-31T04:38:00Z")

</div>

Hi all  
I am trying to parse McFee EPO logs using logstash. I am using the combination of grok and XML filter to parse the log. In the input data set there are few \ within the XML part so I am not able to parse the log in an expected manner.  
I tried Trim and Gsub processors. still, I am getting some errors. Please advise me on this  
i am adding my filter and input XML part, the error message that I am getting now.

---

<div class="post-metadata">

**Author:** ![Ozil](https://avatars.discourse-cdn.com/v4/letter/o/a587f6/32.png) [@Ozil](https://discuss.elastic.co/u/Ozil)\
**Post date:** [January 31, 2020, 4:39am UTC](https://discuss.elastic.co/t/how-to-remove-from-the-existing-log-formate/217295/3 "2020-01-31T04:39:30Z")

</div>

\<29\>1 2020-01-30T06:50:37.0Z HOVMSMAV1 EPOEvents - EventFwd [agentInfo@3401 tenantId="1" bpsId="1" tenantGUID="{00000000-0000-0000-0000-000000000000}" tenantNodePath="1\2"] ï»¿\<?xml version=\"1.0\" encoding=\"UTF-8\"?\>

---

<div class="post-metadata">

**Author:** ![Ozil](https://avatars.discourse-cdn.com/v4/letter/o/a587f6/32.png) [@Ozil](https://discuss.elastic.co/u/Ozil)\
**Post date:** [January 31, 2020, 4:40am UTC](https://discuss.elastic.co/t/how-to-remove-from-the-existing-log-formate/217295/4 "2020-01-31T04:40:11Z")

</div>

[ERROR] 2020-01-30 16:49:54.513 [Ruby-0-Thread-1: /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:22] agent - Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, {, } at line 20, column 18 (byte 297) after filter {\n kv {\n source =\> "message"\n remove\_char\_value =\> "\\"\n}\n}\n\noutput {\nstdout { codec =\> rubydebug }\nelasticsearch {\n hosts =\> ["", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:50:in `compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in `map'", "/usr/share/logstash/logstash-

---

<div class="post-metadata">

**Author:** ![Ozil](https://avatars.discourse-cdn.com/v4/letter/o/a587f6/32.png) [@Ozil](https://discuss.elastic.co/u/Ozil)\
**Post date:** [January 31, 2020, 5:19am UTC](https://discuss.elastic.co/t/how-to-remove-from-the-existing-log-formate/217295/5 "2020-01-31T05:19:11Z")

</div>

filter {  
grok {  
match =\> { "message" =\> '%{SYSLOG5424LINE}' }  
}  
mutate {  
gsub =\> ["syslog5424\_msg","\\",'"']  
}  
xml {  
source =\> "syslog5424\_msg"  
store\_xml =\> false  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2020, 5:19am UTC](https://discuss.elastic.co/t/how-to-remove-from-the-existing-log-formate/217295/6 "2020-02-28T05:19:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
