# LOGSTASH - GSUB - DOESN'T MATCH

**URL:** <https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227>\
**Category:** Logstash\
**Created:** [July 21, 2021, 6:32am UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227 "2021-07-21T06:32:29Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daniel\_Lopez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_lopez/32/50639_2.png) [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Post date:** [July 21, 2021, 6:32am UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/1 "2021-07-21T06:32:29Z")

</div>

Hi

I tried to change a value in a field for use it like id but i couldn't modify the field value with gsub

The data i have in the field is like this: rId = ABC0\_L123456\_789012 and only data i want is 123456 from rId, this is my config

add\_field =\> ["rNum","%{rId}]  
gsub =\> ["rNum","^._L","","rNum","\_._",""]

what I get in elastic is the rId and rNum with the same value, gsub is not working properly with my set tup

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [July 21, 2021, 12:06pm UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/2 "2021-07-21T12:06:59Z")

</div>

Hi,

The main error here is that the use of `.` without any character of repetition.

Error :  
`^.L` search 1 character before a `L` at the beginning of the line.  
Correction :  
`^.*L` search 0 or more character since the beginning of the line until he found a `L` .

Error:  
`_.` search 1 character after a `_`.  
Correction :  
`_.*$` search 0 or more character until the end of the line after a `_`.

So

```auto
gsub => [ 
    "rNum", "^.L", "",
    "rNum", "_.", ""
]

```

Have to be replaced by

```auto
gsub => [ 
    "rNum", "^.*L", "",
    "rNum", "_.*$", ""
]

```

---

<div class="post-metadata">

**Author:** ![Daniel\_Lopez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_lopez/32/50639_2.png) [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Post date:** [July 21, 2021, 5:00pm UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/3 "2021-07-21T17:00:19Z")

</div>

I will try asap

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![Daniel\_Lopez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_lopez/32/50639_2.png) [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Post date:** [July 22, 2021, 9:29am UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/4 "2021-07-22T09:29:36Z")

</div>

It doesn't work, I get the same data in rId and rNum.

BR

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [July 22, 2021, 10:24am UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/5 "2021-07-22T10:24:14Z")

</div>

> [@Daniel\_Lopez](#):
>
> add\_field =\> ["rNum","%{rId}]

Is it write like that in your logstash configuration file ?  
Because add\_field take a hash not an array

---

<div class="post-metadata">

**Author:** ![Daniel\_Lopez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_lopez/32/50639_2.png) [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Post date:** [July 22, 2021, 12:37pm UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/6 "2021-07-22T12:37:50Z")

</div>

add\_field =\> ["rNum","%{rId}"]  
So how could i apply the gsub?

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [July 22, 2021, 1:24pm UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/7 "2021-07-22T13:24:40Z")

</div>

I think the error came from the add\_field.  
In the documentation, about the add\_field, we can found `If this filter is successful, add any arbitrary fields to this event` so i think, the add field is execute after the gsub. That's why rNim and rld have the same value.

Use copy option instead.

```auto
mutate {
    copy => { 
        "rld" => "rNum"
    }
    gsub => [ 
        "rNum", "^.*L", "",
        "rNum", "_.*$", ""
    ]
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 22, 2021, 3:33pm UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/8 "2021-07-22T15:33:14Z")

</div>

> [@Cad](#):
>
> i think, the add field is execute after the gsub

Correct, the order of operations is

- coerce
- rename
- update
- replace
- convert
- gsub
- uppercase
- capitalize
- lowercase
- strip
- remove
- split
- join
- merge
- copy
- add\_field
- remove\_field
- add\_tag
- remove\_tag

---

<div class="post-metadata">

**Author:** ![Daniel\_Lopez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_lopez/32/50639_2.png) [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Post date:** [July 22, 2021, 3:55pm UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/9 "2021-07-22T15:55:06Z")

</div>

Thanks, I will try with copy, but @Badger said that copy is afer gsub, too. Tomorrow i will update you, Thanks!!!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 22, 2021, 4:07pm UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/10 "2021-07-22T16:07:44Z")

</div>

Split the mutate filter into two mutate filters if you want to force the order.

---

<div class="post-metadata">

**Author:** ![Daniel\_Lopez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_lopez/32/50639_2.png) [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Post date:** [July 22, 2021, 6:04pm UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/11 "2021-07-22T18:04:04Z")

</div>

Like this ???

> [@Cad](#):
>
> ```auto
> mutate {
> copy => { 
> "rld" => "rNum"
> }}
> mutate =>{
> gsub => [ 
> "rNum", "^.*L", "",
> "rNum", "_.*$", ""
> ]
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 22, 2021, 6:24pm UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/12 "2021-07-22T18:24:37Z")

</div>

Like that, except you have an extra =\> in the second mutate.

---

<div class="post-metadata">

**Author:** ![Daniel\_Lopez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_lopez/32/50639_2.png) [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Post date:** [July 22, 2021, 8:16pm UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/13 "2021-07-22T20:16:06Z")

</div>

Thanks, tomorrow i will update, thanks!

---

<div class="post-metadata">

**Author:** ![Daniel\_Lopez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_lopez/32/50639_2.png) [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Post date:** [July 23, 2021, 7:18am UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/14 "2021-07-23T07:18:27Z")

</div>

@Badger thanks a lot, two mutates solve my issue!! BR

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 20, 2021, 7:18am UTC](https://discuss.elastic.co/t/logstash-gsub-doesnt-match/279227/15 "2021-08-20T07:18:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
