# How to replace 'special characters' with a logstash filter

**URL:** <https://discuss.elastic.co/t/how-to-replace-special-characters-with-a-logstash-filter/28240>\
**Category:** Logstash\
**Created:** [August 28, 2015, 10:08am UTC](https://discuss.elastic.co/t/how-to-replace-special-characters-with-a-logstash-filter/28240 "2015-08-28T10:08:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![daks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daks/32/3883_2.png) [@daks](https://discuss.elastic.co/u/daks)\
**Post date:** [August 28, 2015, 10:08am UTC](https://discuss.elastic.co/t/how-to-replace-special-characters-with-a-logstash-filter/28240/1 "2015-08-28T10:08:18Z")

</div>

Hello,

I use the IMAP input to retrieve some e-mail (generated by a Windows application) and I can't find how to manipulate the data to do what I want.

E-mails looks like that (simplified and anonymized):

```
Virus/malware : LNK_DUNIHI.SMIX
Computer : HOSTNAME
IP address : aaa.bbb.ccc.ddd
Field1 : Some\Information\Separated\By-Slash\
File : F:\Path to\a\specific file
Date/Time : 27/08/2015 15:48:38
Result : Some description text

```

But Logstash sees them like that (at least this is what I see if I retrieve them with just an input/file and output/file):

```
Virus/malware : LNK_DUNIHI.SMIX\r\nComputer : HOSTNAME\r\nIP address : aaa.bbb.ccc.ddd\r\nField1 : Some\\Information\\Separated\\By-Slash\\\r\nFile : F:\\Path to\\a\\specific file\r\nDate/Time : 27/08/2015 15:48:38\r\nResult : Some description text

```

-\> all newlines are converted to '\r\n' and all '' to '\\'

I try to make the message easy to read and grok (this is the initial need but '\\' causes problem) so I want to replace all '\r\n' to something else and '\\' to ''. The first one is ok but the second one not. I use a mutate/gsub filter like this:

```
mutate {
    gsub => [
        "message", "\r\n", "X",
        "message", "\\", "Y"
    ]
}

```

The first gsub expression works, the second one never, I got the following message:

```
Error: Expected one of #, {, ,, ] at line 23, column 31 (byte 542) after filter {
    
    mutate {
        gsub => [
            "message", "\r\n", "X",
            "message", "\\", "

```

Maybe there is a syntax error but I don't find it, maybe there is a problem with special characters like \ which needs to be protected by another \ but I tried putting '\\' with the same error.

Anyone can help me with this?

---

<div class="post-metadata">

**Author:** ![DracoBlue](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dracoblue/32/4362_2.png) [@DracoBlue](https://discuss.elastic.co/u/DracoBlue)\
**Post date:** [August 29, 2015, 9:51pm UTC](https://discuss.elastic.co/t/how-to-replace-special-characters-with-a-logstash-filter/28240/2 "2015-08-29T21:51:45Z")

</div>

It seems like logstash has some issues, when it comes to escaping things. See:

[https://logstash.jira.com/browse/LOGSTASH-1377](https://logstash.jira.com/browse/LOGSTASH-1377)

and

> <https://github.com/elastic/logstash/issues/1645>

for more information.

According to: [https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-gsub](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-gsub) the following should replace backslashes, question marks, hashes and minuses:

```
filter {
  mutate {
    gsub => [
      # replace backslashes, question marks, hashes, and minuses
      # with a dot "."
      "fieldname2", "[\\?#-]", "."
    ]
  }
}

```

Maybe it works, if you use "[\]" ?

---

<div class="post-metadata">

**Author:** ![daks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daks/32/3883_2.png) [@daks](https://discuss.elastic.co/u/daks)\
**Post date:** [September 1, 2015, 8:46am UTC](https://discuss.elastic.co/t/how-to-replace-special-characters-with-a-logstash-filter/28240/3 "2015-09-01T08:46:54Z")

</div>

Thanks for this tip, even if it don't work in my case.  
I finally kept the first mutate/gsub filter for '\r\n' and enhanced my grok filter to better parse the fields. For now, I'll keep my double backslash as-is.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:30am UTC](https://discuss.elastic.co/t/how-to-replace-special-characters-with-a-logstash-filter/28240/4 "2017-07-06T05:30:24Z")

</div>


