# Logstash regexp if not working

**URL:** <https://discuss.elastic.co/t/logstash-regexp-if-not-working/88488>\
**Category:** Logstash\
**Created:** [June 6, 2017, 11:18pm UTC](https://discuss.elastic.co/t/logstash-regexp-if-not-working/88488 "2017-06-06T23:18:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rpuserh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rpuserh/32/63367_2.png) [@rpuserh](https://discuss.elastic.co/u/rpuserh)\
**Post date:** [June 6, 2017, 11:18pm UTC](https://discuss.elastic.co/t/logstash-regexp-if-not-working/88488/1 "2017-06-06T23:18:43Z")

</div>

hi,  
I have JSON which has key body.message and content of this key can be JSON[OBJECT] or text (I cant insert like this to ES as it giving mapping error)  
I want to move it to another field if it look like text and exists  
But this config is not working (Now it matching everything)  
Please help me,

Thanks in advance.

```
            # if not look like json and exists move to other field and remove source
            if [body][message] !~ /{.*}/ and [body][message] {

                            mutate {
                                    add_field => { "message_text" => "%{[body][message]}" }
                                    remove_field => ["[body][message]" ]
                            }
                    }
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 11, 2017, 12:47pm UTC](https://discuss.elastic.co/t/logstash-regexp-if-not-working/88488/2 "2017-06-11T12:47:53Z")

</div>

Have you tried escaping the braces (which has a special meaning in regular expressions)? You should probably also use `^` and `$` anchors so that you don't match braces anywhere in the string.

---

<div class="post-metadata">

**Author:** ![rpuserh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rpuserh/32/63367_2.png) [@rpuserh](https://discuss.elastic.co/u/rpuserh)\
**Post date:** [June 12, 2017, 6:08pm UTC](https://discuss.elastic.co/t/logstash-regexp-if-not-working/88488/3 "2017-06-12T18:08:26Z")

</div>

Yes I tried no success.  
But i have done it with ruby  
This ruby solution I liked more as I'm checking if key value is JSON

```
ruby {
    code => "if event.get('[body][message]').class == Hash ; event.set('message_text' , event.get('[body][message]')) ; event.remove('[body][message]') end"
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2017, 6:09pm UTC](https://discuss.elastic.co/t/logstash-regexp-if-not-working/88488/4 "2017-07-10T18:09:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
