# Logstash 8.5.2 how to parse special character in a string value

**URL:** <https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107>\
**Category:** Logstash\
**Created:** [January 27, 2023, 12:35pm UTC](https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107 "2023-01-27T12:35:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [January 27, 2023, 12:35pm UTC](https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107/1 "2023-01-27T12:35:40Z")

</div>

Parsing a value of string field `http://127.0.0.1:27336/notify`  
logstash maps in Elastic search index many values for the original string.  
In this case values are `http`, `127.0.0.1`, `27336` and `notify`.  
When it encounters the characters `:` and `/` splits the original string.  
While in output I expect to see the string as it arrives in input: `http://127.0.0.1:27336/notify`.  
This is my logstash.conf

```auto
input {
    beats {
        port => 5042
    }
}
output {
    elasticsearch {
        hosts => ["http://XX.X.X.XXX:XXXX"]
        index => "example"
		user => "user"
		password => "password"
    }
}

```

Is there a filter that allows me to ignore these special characters?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 27, 2023, 1:07pm UTC](https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107/2 "2023-01-27T13:07:02Z")

</div>

It is not clear what is your issue, the Logstash pipeline you shared does not have any filter, so it will not parse or change your message in any way.

Please share a sample of your source message and also the output of the same message you are getting in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![gaetano](https://avatars.discourse-cdn.com/v4/letter/g/b9e5f3/32.png) [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Post date:** [January 27, 2023, 1:11pm UTC](https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107/3 "2023-01-27T13:11:19Z")

</div>

my source message is `http://127.0.0.1:27336/notify`

In output I have  
`http`  
`127.0.0.1`  
`27336`  
`notify`

I would like to have this output:  
`http://127.0.0.1:27336/notify`

What filter should I use to get the desired output?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 27, 2023, 1:14pm UTC](https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107/4 "2023-01-27T13:14:10Z")

</div>

You need to share your message and the output Logstash is giving to you, it is not possible to understand your issue without this.

Are you using Filebeat, right? The file that Filebeat is reading has a line where you have only this ` http://127.0.0.1:27336/notify` as a message?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2023, 1:14pm UTC](https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107/5 "2023-02-24T13:14:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
