# LogStash Special Character Split Error

**URL:** <https://discuss.elastic.co/t/logstash-special-character-split-error/295137>\
**Category:** Logstash\
**Created:** [January 23, 2022, 9:59am UTC](https://discuss.elastic.co/t/logstash-special-character-split-error/295137 "2022-01-23T09:59:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![eagles40cnuh](https://avatars.discourse-cdn.com/v4/letter/e/edb3f5/32.png) [@eagles40cnuh](https://discuss.elastic.co/u/eagles40cnuh)\
**Post date:** [January 23, 2022, 9:59am UTC](https://discuss.elastic.co/t/logstash-special-character-split-error/295137/1 "2022-01-23T09:59:46Z")

</div>

Hi! I have some problem with Logstash Filter

1. Filebeat collect -\> "aaa.log" file
2. and then message field -\> "ID∮NAME∮TELNO"
3. And Logstash.conf is

input {  
beats { port =\> xxxx  
}

filter {  
mutate {  
split =\> { "message" =\> "∮" }  
}  
}

output {  
stdout {}  
}

1. But LogStash Console Output Error  
"The following config files contains non-ascii characters but are not UTF-8 encoded"

2. Therefore.. I did some test.... Original logfile content & Logstash Conf change

- "ID∮NAME∮TELNO" -\> "ID,NAME,TELNO"
- split =\> { "message" =\> "," }

1. Then Logstash filter Split success

But I need "∮" special character split pattern.  
Is there any way to do it?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [January 23, 2022, 11:54am UTC](https://discuss.elastic.co/t/logstash-special-character-split-error/295137/2 "2022-01-23T11:54:29Z")

</div>

Are you doing something different than this? It works for me.

**Conf**

```auto
input {
  generator {
    message => '[{ "message": "ID∮NAME∮TELNO" }]'
    count => 1
    codec => "json"
  }
}
filter {
  mutate {
    split => { "message" => "∮" }
  }  
}
output {
  stdout { codec => "json" }
}

```

**Output**

```auto
{
    "message": [
        "ID",
        "NAME",
        "TELNO"
    ],
    "host": "Aarons-MacBook-Pro.local",
    "@version": "1",
    "@timestamp": "2022-01-23T11:52:17.130Z",
    "sequence": 0
}

```

---

<div class="post-metadata">

**Author:** ![eagles40cnuh](https://avatars.discourse-cdn.com/v4/letter/e/edb3f5/32.png) [@eagles40cnuh](https://discuss.elastic.co/u/eagles40cnuh)\
**Post date:** [January 23, 2022, 12:13pm UTC](https://discuss.elastic.co/t/logstash-special-character-split-error/295137/3 "2022-01-23T12:13:02Z")

</div>

In my case Output... like this

[2022-01-23T21:09:36,704][ERROR][logstash.config.sourceloader] Could not fetch all the sources {:exception=\>LogStash::ConfigLoadingError, :message=\>"The following config files contains non-ascii characters but are not UTF-8 encoded ["c:/logstash-7.16.3/config/logstash.conf"]", :backtrace=\>["C:/logstash-7.16.3/logstash-core/lib/logstash/config/source/local.rb:99:in `read'", "C:/logstash-7.16.3/logstash-core/lib/logstash/config/source/local.rb:110:in `read'", "C:/logstash-7.16.3/logstash-core/lib/logstash/config/source/local.rb:206:in `local_pipeline_configs'", "C:/logstash-7.16.3/logstash-core/lib/logstash/config/source/local.rb:177:in `pipeline\_configs'", "C:/logstash-7.16.3/logstash-core/lib/logstash/config/source\_loader.rb:76:in `block in fetch'", "org/jruby/RubyArray.java:2584:in `collect'", "C:/logstash-7.16.3/logstash-core/lib/logstash/config/source\_loader.rb:75:in `fetch'", "C:/logstash-7.16.3/logstash-core/lib/logstash/agent.rb:182:in `converge\_state\_and\_update'", "C:/logstash-7.16.3/logstash-core/lib/logstash/agent.rb:120:in `execute'", "C:/logstash-7.16.3/logstash-core/lib/logstash/runner.rb:432:in `block in execute'", "C:/logstash-7.16.3/vendor/bundle/jruby/2.5.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}

1. Most of Special Character is Output Normal (Ex) "/", "#", "@", "!"

"message" =\> [  
[0] "ID",  
[1] "NAME",  
[2] "TELNO"  
]

But "§" is Error..

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 23, 2022, 3:23pm UTC](https://discuss.elastic.co/t/logstash-special-character-split-error/295137/4 "2022-01-23T15:23:44Z")

</div>

This is really weird, I simulated with the same symbol in the pipeline and it worked without any problem.

But I'm on a Linux system and from the output of @aaron-nimocks example, he is on a Mac, which is Unix based, maybe it is something related to how windows is encoding the configuration file, this can give some problems in some cases.

You could try to not use the ∮ char but use its unicode code, you would need to replace it with another character to use in the split filter.

This works:

```auto
mutate {
    gsub => ["message","\u222E","|"]
}
mutate {
    split => {"message" => "|"}
}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 23, 2022, 3:29pm UTC](https://discuss.elastic.co/t/logstash-special-character-split-error/295137/5 "2022-01-23T15:29:22Z")

</div>

Just one thing to avoid confusion which is the character that you want to use in the split filter?

Your original message is that `ID∮NAME∮TELNO`, so you would split on this character ∮, which is a math symbol representing a contour integral.

But your last message you shared this other symbol `§`, which is a different one, this is a section sign, used to reference individual sections on a document, they look similar but are completely different.

The `gsub` approach still work, you just would need to use the correct code, if this is indeed the split character.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 23, 2022, 4:12pm UTC](https://discuss.elastic.co/t/logstash-special-character-split-error/295137/6 "2022-01-23T16:12:17Z")

</div>

Which editor do you use to create logstash.conf?

"/", "#", "@", "!" are ASCII characters and could make no error.  
There are some encodings which share ASCII part of character codes with UTF-8 and other part are completely different. One example is Shift-JIS in Japan and there maybe some for other CJK characters.

Please check the encoding of logstash.conf.

---

<div class="post-metadata">

**Author:** ![eagles40cnuh](https://avatars.discourse-cdn.com/v4/letter/e/edb3f5/32.png) [@eagles40cnuh](https://discuss.elastic.co/u/eagles40cnuh)\
**Post date:** [January 24, 2022, 9:10am UTC](https://discuss.elastic.co/t/logstash-special-character-split-error/295137/7 "2022-01-24T09:10:40Z")

</div>

Thanks leandrojmp and Tomo\_M

I followed you adivce.. my **"logstash.conf"** Encoding Change  
and then This problem has been resolved!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2022, 9:11am UTC](https://discuss.elastic.co/t/logstash-special-character-split-error/295137/8 "2022-02-21T09:11:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
