# Logstash - json filter removes backslash

**URL:** <https://discuss.elastic.co/t/logstash-json-filter-removes-backslash/164285>\
**Category:** Logstash\
**Created:** [January 15, 2019, 10:05am UTC](https://discuss.elastic.co/t/logstash-json-filter-removes-backslash/164285 "2019-01-15T10:05:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Francisca\_Lima](https://avatars.discourse-cdn.com/v4/letter/f/edb3f5/32.png) [@Francisca\_Lima](https://discuss.elastic.co/u/Francisca_Lima)\
**Post date:** [January 15, 2019, 10:05am UTC](https://discuss.elastic.co/t/logstash-json-filter-removes-backslash/164285/1 "2019-01-15T10:05:04Z")

</div>

Hello,  
When I am doing a json filter in my logstash file, in fields where I have two backlashes ("\") one of them is removed. Why this is happening? Besides replacing \ to \, what can I do?

Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 15, 2019, 2:38pm UTC](https://discuss.elastic.co/t/logstash-json-filter-removes-backslash/164285/2 "2019-01-15T14:38:24Z")

</div>

Can you show an example of the json? Please indent it by 4 spaces, otherewise the backslashes will not display correctly.

Where are you seeing one of the backslashes has been removed?

---

<div class="post-metadata">

**Author:** ![Francisca\_Lima](https://avatars.discourse-cdn.com/v4/letter/f/edb3f5/32.png) [@Francisca\_Lima](https://discuss.elastic.co/u/Francisca_Lima)\
**Post date:** [January 16, 2019, 12:29pm UTC](https://discuss.elastic.co/t/logstash-json-filter-removes-backslash/164285/3 "2019-01-16T12:29:52Z")

</div>

In the original file I have "XYZ\\ABC", but when I use the json filter and inserting those data in elastic, I have "XYZ\ABC" (one backslash is lost). I tried to use: mutate { gsub =\> ["robotName","\","\\"]}  
But, appears the error: Expected one of #, {, ,, ] at line...  
How can I do to replace the backslash? Another way to use the gsub?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 16, 2019, 12:31pm UTC](https://discuss.elastic.co/t/logstash-json-filter-removes-backslash/164285/4 "2019-01-16T12:31:24Z")

</div>

Can you show the complete error message and configuration? The error message does tell you exactly where in the configuration the problem is.

---

<div class="post-metadata">

**Author:** ![Francisca\_Lima](https://avatars.discourse-cdn.com/v4/letter/f/edb3f5/32.png) [@Francisca\_Lima](https://discuss.elastic.co/u/Francisca_Lima)\
**Post date:** [January 16, 2019, 2:08pm UTC](https://discuss.elastic.co/t/logstash-json-filter-removes-backslash/164285/5 "2019-01-16T14:08:57Z")

</div>

When I insert the gsub, everything it was fine, but I save and run and some character appears in the gsub. I tried to delete but it appears again. I fixed using the gsub in ruby code. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2019, 2:08pm UTC](https://discuss.elastic.co/t/logstash-json-filter-removes-backslash/164285/6 "2019-02-13T14:08:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
