# Logstash http\_poller body escape double and single quotation marks

**URL:** <https://discuss.elastic.co/t/logstash-http-poller-body-escape-double-and-single-quotation-marks/282039>\
**Category:** Logstash\
**Created:** [August 20, 2021, 7:02am UTC](https://discuss.elastic.co/t/logstash-http-poller-body-escape-double-and-single-quotation-marks/282039 "2021-08-20T07:02:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![zhyp](https://avatars.discourse-cdn.com/v4/letter/z/91b2a8/32.png) [@zhyp](https://discuss.elastic.co/u/zhyp)\
**Post date:** [August 20, 2021, 7:02am UTC](https://discuss.elastic.co/t/logstash-http-poller-body-escape-double-and-single-quotation-marks/282039/1 "2021-08-20T07:02:24Z")

</div>

Hi  
I used logstash http\_ poller calls the SQL API of elasticsearch. There are double quotation marks and single quotation marks in the body.  
Here is the body I tested.  
body =\> '{"query": "SELECT \* FROM test WHERE name = '123'"}'  
If \ is used to escape single quotation marks, an error will be reported.  
The following is the error message.

{  
"status" =\> 400,  
"@version" =\> "1",  
"@timestamp" =\> 2021-08-20T06:30:05.298Z,  
"error" =\> {  
"caused\_by" =\> {  
"type" =\> "json\_parse\_exception",  
"reason" =\> "Unrecognized character escape ''' (code 39)\n at [Source: (org.elasticsearch.common.io.stream.InputStreamStreamInput); line: 1, column: 46]"  
},  
"root\_cause" =\> [  
[0] {  
"type" =\> "x\_content\_parse\_exception",  
"reason" =\> "[1:11] [sql/query] failed to parse field [query]"  
}  
],  
"type" =\> "x\_content\_parse\_exception",  
"reason" =\> "[1:11] [sql/query] failed to parse field [query]"  
}  
}

---

<div class="post-metadata">

**Author:** ![jenhouwu](https://avatars.discourse-cdn.com/v4/letter/j/2bfe46/32.png) [@jenhouwu](https://discuss.elastic.co/u/jenhouwu)\
**Post date:** [August 23, 2021, 10:16am UTC](https://discuss.elastic.co/t/logstash-http-poller-body-escape-double-and-single-quotation-marks/282039/2 "2021-08-23T10:16:29Z")

</div>

> [@zhyp](#):
>
> body =\> '{"query": "SELECT \* FROM test WHERE name = '123'"}'

Try this  
**body =\> '{"query": "SELECT \* FROM test WHERE name = \u0027123\u0027"}'**

---

<div class="post-metadata">

**Author:** ![zhyp](https://avatars.discourse-cdn.com/v4/letter/z/91b2a8/32.png) [@zhyp](https://discuss.elastic.co/u/zhyp)\
**Post date:** [August 24, 2021, 1:38am UTC](https://discuss.elastic.co/t/logstash-http-poller-body-escape-double-and-single-quotation-marks/282039/3 "2021-08-24T01:38:21Z")

</div>

🙂 Thank you for your reply. You are right.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2021, 1:39am UTC](https://discuss.elastic.co/t/logstash-http-poller-body-escape-double-and-single-quotation-marks/282039/4 "2021-09-21T01:39:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
