# Logstash strip string from field

**URL:** <https://discuss.elastic.co/t/logstash-strip-string-from-field/280233>\
**Category:** Logstash\
**Created:** [August 2, 2021, 3:08pm UTC](https://discuss.elastic.co/t/logstash-strip-string-from-field/280233 "2021-08-02T15:08:33Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hamza\_El\_Aouane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_el_aouane/32/82411_2.png) [@Hamza\_El\_Aouane](https://discuss.elastic.co/u/Hamza_El_Aouane)\
**Post date:** [August 2, 2021, 3:08pm UTC](https://discuss.elastic.co/t/logstash-strip-string-from-field/280233/1 "2021-08-02T15:08:33Z")

</div>

Hi guys.

In my logstash stream, I have a some filter to add a fields which is the merging of other fields.

as follow:

```auto
if [destinationUserName] and [sourceUserName] {
    mutate { add_field => { "userID" => "%{ad.loginName}" } }
} else if [destinationUserName] {
    mutate { add_field => { "userID" => "%{destinationUserName}" } }
} else if [sourceUserName] {
    mutate { add_field => { "userID" => "%{sourceUserName}" } }

```

this works just file, expect the field `ad.loginName` is a field that looks like this

```auto
ad.loginName
user\0001

```

when the merge happens, my userID field looks like this.

```auto
userID
user\0001

```

I was wondering if there is a way how i can strip the `user\`and keep only the number so that in the userID I will have some thing like this

```auto
userID
0001

```

thank you very much for any help you can provide

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 2, 2021, 3:18pm UTC](https://discuss.elastic.co/t/logstash-strip-string-from-field/280233/2 "2021-08-02T15:18:56Z")

</div>

Try

```
mutate { gsub => ["ad.loginName", "user[\\]", "" ] }
```

---

<div class="post-metadata">

**Author:** ![Hamza\_El\_Aouane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_el_aouane/32/82411_2.png) [@Hamza\_El\_Aouane](https://discuss.elastic.co/u/Hamza_El_Aouane)\
**Post date:** [August 2, 2021, 4:25pm UTC](https://discuss.elastic.co/t/logstash-strip-string-from-field/280233/3 "2021-08-02T16:25:41Z")

</div>

thank you very much for your reply and solution. I do have another question about this process.  
because the stripping, forced the new field do drop all the leading zero. can I post the question here or open a new topic for it?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 2, 2021, 4:41pm UTC](https://discuss.elastic.co/t/logstash-strip-string-from-field/280233/4 "2021-08-02T16:41:08Z")

</div>

You could use

```
mutate { gsub => ["ad.loginName", "^0+", ""] }`
```

---

<div class="post-metadata">

**Author:** ![Hamza\_El\_Aouane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_el_aouane/32/82411_2.png) [@Hamza\_El\_Aouane](https://discuss.elastic.co/u/Hamza_El_Aouane)\
**Post date:** [August 2, 2021, 4:44pm UTC](https://discuss.elastic.co/t/logstash-strip-string-from-field/280233/5 "2021-08-02T16:44:19Z")

</div>

sorry for this question, I just want to understand that bit of code.

```auto
mutate { gsub => ["ad.loginName", "^0+", ""] }

```

will simply keep the zeros that had before right?

so if it has 3 zeros, will keep them?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 2, 2021, 4:58pm UTC](https://discuss.elastic.co/t/logstash-strip-string-from-field/280233/6 "2021-08-02T16:58:14Z")

</div>

^ anchors the pattern to the beginning of the string. + means "one or more". So this will replace one or more zeroes at the start of the string with "". That is, it will delete them.

---

<div class="post-metadata">

**Author:** ![Hamza\_El\_Aouane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_el_aouane/32/82411_2.png) [@Hamza\_El\_Aouane](https://discuss.elastic.co/u/Hamza_El_Aouane)\
**Post date:** [August 2, 2021, 5:01pm UTC](https://discuss.elastic.co/t/logstash-strip-string-from-field/280233/7 "2021-08-02T17:01:49Z")

</div>

Perfect, but I want to keep the zeros not remove them.

right now if we consider this original string:

```auto
user\0001

```

after the gsub on the first solution, I am having his output

```auto
1

```

I believe that logstash drops the leading zeros, but I would like to keep them. So as a output after the gsub, I would like to have this

```auto
0001

```

sorry if I didn't explained clearly my problem before.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 2, 2021, 5:21pm UTC](https://discuss.elastic.co/t/logstash-strip-string-from-field/280233/8 "2021-08-02T17:21:57Z")

</div>

Are you saying that

```
mutate { gsub => ["ad.loginName", "user[\\]", "" ] }

```

removes the zeroes? I can only see that happening if the string is being converted to an integer.

---

<div class="post-metadata">

**Author:** ![Hamza\_El\_Aouane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_el_aouane/32/82411_2.png) [@Hamza\_El\_Aouane](https://discuss.elastic.co/u/Hamza_El_Aouane)\
**Post date:** [August 2, 2021, 5:24pm UTC](https://discuss.elastic.co/t/logstash-strip-string-from-field/280233/9 "2021-08-02T17:24:16Z")

</div>

Yes, the

`mutate { gsub => ["ad.loginName", "user[\\]", "" ] }`

is removing the zeroes also.

Oh ok, so it ok, I will find another way how to process that field, because converting the field to a integer might cause errors in the future probably. thank you very much for your help and time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2021, 5:24pm UTC](https://discuss.elastic.co/t/logstash-strip-string-from-field/280233/10 "2021-08-30T17:24:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
