# Logstash windows memory offset delete

**URL:** <https://discuss.elastic.co/t/logstash-windows-memory-offset-delete/240347>\
**Category:** Logstash\
**Created:** [July 8, 2020, 12:42pm UTC](https://discuss.elastic.co/t/logstash-windows-memory-offset-delete/240347 "2020-07-08T12:42:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![amaleswar](https://avatars.discourse-cdn.com/v4/letter/a/e47774/32.png) [@amaleswar](https://discuss.elastic.co/u/amaleswar)\
**Post date:** [July 8, 2020, 12:42pm UTC](https://discuss.elastic.co/t/logstash-windows-memory-offset-delete/240347/1 "2020-07-08T12:42:10Z")

</div>

Hello Team,

I want to delete anything after dll, example showing below. I`m trying to use mutate gsub but failing

Parsed data:  
"CallTrace" =\> [  
[0] "c:\windows\system32\nll.dll+92c34",  
[1] "c:\windows\system32\kerase.dll+6a7f5",  
[2] "c:\windows\system32\lsm.dll+ff97",  
]

After Applying gsub  
gsub =\> [  
"[winlog][event\_data][CallTrace]", "[+.{1,5}]", ""  
]

Output after gsub applied:

```
                [0] "c:\\windows\\system32\\nlldll9c34",
                [1] "c:\\windows\\system32\\kerasedll6a7f",
                [2] "c:\\windows\\system32\\lsmdllff97"

```

Expected Output:

[0] "c:\windows\system32\nll.dll  
[1] "c:\windows\system32\kerase.dll  
[2] "c:\windows\system32\lsm.dll

My target is to remove everything after .dll in array using gsub or any other

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 8, 2020, 12:56pm UTC](https://discuss.elastic.co/t/logstash-windows-memory-offset-delete/240347/2 "2020-07-08T12:56:53Z")

</div>

`[+.{1,5}]` is a character set and searches for `+`, `.`, `{`, `1`, `,`, `5` and `}`.  
`\+.{1,5}` is what you actually wanted to do (The plus and one to five characters after it.)  
If you want to delete the plus and anything after it, it would be `\+.*`  
Anything after `.dll`, even if there is no plus, would be `(?<=\.dll).*`

---

<div class="post-metadata">

**Author:** ![amaleswar](https://avatars.discourse-cdn.com/v4/letter/a/e47774/32.png) [@amaleswar](https://discuss.elastic.co/u/amaleswar)\
**Post date:** [July 8, 2020, 1:25pm UTC](https://discuss.elastic.co/t/logstash-windows-memory-offset-delete/240347/3 "2020-07-08T13:25:07Z")

</div>

Hello Jenni Thanks for the response. I tried the option above, since array of objects it is working only 1 line.

Here is the result

"CallTrace" =\> [  
[0] "c:\windows\system32\ntdll.dll"  
],

not working on remaining.

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 8, 2020, 2:02pm UTC](https://discuss.elastic.co/t/logstash-windows-memory-offset-delete/240347/4 "2020-07-08T14:02:30Z")

</div>

Strange, I just tried this test configuration in Logstash 7.7.1 with logstash-filter-mutate (3.5.0):

```
input {
	stdin{}
}
filter {
	mutate {
		add_field => {
			"[winlog][event_data][CallTrace]" => [
				"c:\windows\system32\nll.dll+92c34",
				"c:\windows\system32\kerase.dll+6a7f5",
				"c:\windows\system32\lsm.dll+ff97"
			]
		}
	}
	mutate {
		gsub => [
			"[winlog][event_data][CallTrace]", "(?<=\.dll).*", ""
		]
	}
}
output {
	stdout {}
}

```

and got:

```
{
    "@timestamp" => 2020-07-08T13:58:51.069Z,
       "message" => "warghs",
          "host" => "##########",
      "@version" => "1",
        "winlog" => {
        "event_data" => {
            "CallTrace" => [
                [0] "c:\\windows\\system32\\nll.dll",
                [1] "c:\\windows\\system32\\kerase.dll",
                [2] "c:\\windows\\system32\\lsm.dll"
            ]
        }
    }
}
```

---

<div class="post-metadata">

**Author:** ![amaleswar](https://avatars.discourse-cdn.com/v4/letter/a/e47774/32.png) [@amaleswar](https://discuss.elastic.co/u/amaleswar)\
**Post date:** [July 8, 2020, 4:17pm UTC](https://discuss.elastic.co/t/logstash-windows-memory-offset-delete/240347/5 "2020-07-08T16:17:28Z")

</div>

Found the issue. I suppose to use other mutate block instead of one. Thanks for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2020, 4:17pm UTC](https://discuss.elastic.co/t/logstash-windows-memory-offset-delete/240347/6 "2020-08-05T16:17:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
