# \[Logstash\] Peut-on supprimer un backslash?

**URL:** <https://discuss.elastic.co/t/logstash-peut-on-supprimer-un-backslash/201416>\
**Category:** Discussions en français\
**Created:** [September 27, 2019, 2:21pm UTC](https://discuss.elastic.co/t/logstash-peut-on-supprimer-un-backslash/201416 "2019-09-27T14:21:43Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [September 30, 2019, 7:32am UTC](https://discuss.elastic.co/t/logstash-peut-on-supprimer-un-backslash/201416/3 "2019-09-30T07:32:42Z")

</div>

> [@How to replace 'special characters' with a logstash filter](https://discuss.elastic.co/t/how-to-replace-special-characters-with-a-logstash-filter/28240/2):
>
> It seems like logstash has some issues, when it comes to escaping things. See: [https://logstash.jira.com/browse/LOGSTASH-1377](https://logstash.jira.com/browse/LOGSTASH-1377) and for more information. According to: [https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-gsub](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-gsub) the following should replace backslashes, question marks, hashes and minuses: filter { mutate { gsub =\> [ # replace backslashes, question marks, hashes, and minuses # with a dot "." "fieldname2", "[…

> <https://github.com/logstash-plugins/logstash-filter-mutate/issues/40>
>
> For some reason the log source (which I don't control over) is sending lines wit…h escaped signs:
> 
> \`\`\`
> $ cat notOK\_sample.log
> field1 field2 field3 \\"field 4\\" field5
> \`\`\`
> 
> I'm using the cvs filter as the main matching filter, it works well for the standardized/expected lines:
> 
> \`\`\`
> $ cat OK\_sample.log
> field1 field2 field3 "field 4" field5
> \`\`\`
> 
> In order to normalize the log lines, I thought about applying gsub to look for \`\\"\` and replace to \`"\`, however it doesn't work (attempt 1,2). It does work if I choose other char, space, or nothing though (attempts 3,4).
> \- Attempt # 1
> 
> input line: \`\\"field4\\"\`
> gsub filter: \`\["message", "\\\\\\"", "\\"" \]\`
> 
> Rubydebug: 
> got: \`\\\\\\"field4\\\\\\"\`
> expected: \`\\"field4\\"\`
> \- Attempt # 2
> 
> input line: \`\\"field4\\"\`
> gsub filter: \`\["message", "\\\\\\"", "\\\\"" \]\`
> 
> Rubydebug: 
> got: \`\\\\\\"field4\\\\\\"\`
> expected: \`\\"field4\\"\`
> \- Attempt # 3 
> 
> input line: \`\\"field4\\"\`
> gsub filter: \`\["message", "\\\\\\"", "" \]\`
> 
> Rubydebug: 
> got: \`field4\`
> expected: \`field4\`
> \- Attemp # 4
> 
> input line: \`\\"field4\\"\`
> gsub filter: \`\["message", "\\\\\\"", "x" \]\`
> 
> Rubydebug: 
> got: \`xfield4x\`
> expected: \`xfield4x\`
> 
> Info:
> 
> \`\`\`
> $ ~/logstash-1.5.3/bin/logstash -V
> logstash 1.5.3
> \`\`\`
> 
> \`\`\`
> $ sw\_vers
> ProductName: Mac OS X
> ProductVersion: 10.10.4
> BuildVersion: 14E46
> \`\`\`
> 
> \`\`\`
> $ ruby -v
> ruby 2.0.0p481 (2014-05-08 revision 45883) \[universal.x86\_64-darwin14\]
> \`\`\`

---

_[View the full topic](https://discuss.elastic.co/t/logstash-peut-on-supprimer-un-backslash/201416)._
