# Logstash | Pipeline - Hexadecimal to ASCII Converter

**URL:** <https://discuss.elastic.co/t/logstash-pipeline-hexadecimal-to-ascii-converter/223155>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [March 11, 2020, 2:18pm UTC](https://discuss.elastic.co/t/logstash-pipeline-hexadecimal-to-ascii-converter/223155 "2020-03-11T14:18:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![deeshu](https://avatars.discourse-cdn.com/v4/letter/d/50afbb/32.png) [@deeshu](https://discuss.elastic.co/u/deeshu)\
**Post date:** [March 11, 2020, 2:18pm UTC](https://discuss.elastic.co/t/logstash-pipeline-hexadecimal-to-ascii-converter/223155/1 "2020-03-11T14:18:37Z")

</div>

Hi experts,  
I am trying to parse some events from Auditd, the values have been extracted but the commands executed are coming in hexadecimal format.

Can anyone help how to convert it to ASCII in a logstash pipeline.  
Below is the sample logs and logic I am using to convert but no joy ☹

type=PROCTITLE msg=audit(1583935996.510:284168): proctitle=2F7573722F7362696E2F6E747064002D70002F7661722F72756E2F6E74702F6E7470642E706964002D67002D75006E74703A6E7470002D63002F6574632F6E74702E636F6E66

if [message] =~ "PROCTITLE" {  
ruby { code =\> "event.set('[auditd][log][proctitle]',event.get('[audit][log][proctitle]').pack('H\*'))" }  
}

@Badger Any inputs here from your expertise?

TIA,  
Deepak Shukla

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 11, 2020, 4:59pm UTC](https://discuss.elastic.co/t/logstash-pipeline-hexadecimal-to-ascii-converter/223155/2 "2020-03-11T16:59:17Z")

</div>

> [@deeshu](#):
>
> ruby { code =\> "event.set('[auditd][log][proctitle]',event.get('[audit][log][proctitle]').pack('H\*'))" }

.pack operates on an array, not on a string. If you have a field called proctitle then

```
ruby { code => "event.set('[proctitle]', [event.get('[proctitle]')].pack('H*'))" }

```

will get you

```
"/usr/sbin/ntpd\x00-p\x00/var/run/ntp/ntpd.pid\x00-g\x00-u\x00ntp:ntp\x00-c\x00/etc/ntp.conf

```

which looks like it is encoding spaces with NUL.

---

<div class="post-metadata">

**Author:** ![ankitsynX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitsynx/32/64535_2.png) [@ankitsynX](https://discuss.elastic.co/u/ankitsynX)\
**Post date:** [March 12, 2020, 2:56pm UTC](https://discuss.elastic.co/t/logstash-pipeline-hexadecimal-to-ascii-converter/223155/3 "2020-03-12T14:56:28Z")

</div>

Hi Deepak,

Please use the .split.pack() for string inputs as @Badger explained .pack operates on an array.

> ruby { code =\> "event.set('[auditd][log][proctitle]'),event.get('[auditd][log][proctitle]').split.pack('H\*'))"}

Hopefully this should work for you.

Ankit

---

<div class="post-metadata">

**Author:** ![deeshu](https://avatars.discourse-cdn.com/v4/letter/d/50afbb/32.png) [@deeshu](https://discuss.elastic.co/u/deeshu)\
**Post date:** [March 13, 2020, 8:53am UTC](https://discuss.elastic.co/t/logstash-pipeline-hexadecimal-to-ascii-converter/223155/4 "2020-03-13T08:53:44Z")

</div>

Thanks Ankit.... It worked!

---

<div class="post-metadata">

**Author:** ![deeshu](https://avatars.discourse-cdn.com/v4/letter/d/50afbb/32.png) [@deeshu](https://discuss.elastic.co/u/deeshu)\
**Post date:** [March 13, 2020, 8:54am UTC](https://discuss.elastic.co/t/logstash-pipeline-hexadecimal-to-ascii-converter/223155/5 "2020-03-13T08:54:21Z")

</div>

Thanks for your heads up Badger on the string and array part!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2020, 8:54am UTC](https://discuss.elastic.co/t/logstash-pipeline-hexadecimal-to-ascii-converter/223155/6 "2020-04-10T08:54:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
