# Management of illegal characters

**URL:** <https://discuss.elastic.co/t/management-of-illegal-characters/377159>\
**Category:** Logstash\
**Created:** [April 15, 2025, 4:36pm UTC](https://discuss.elastic.co/t/management-of-illegal-characters/377159 "2025-04-15T16:36:53Z")\
**Posts on this page:** 1\
**Showing post:** 9

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 15, 2025, 11:46pm UTC](https://discuss.elastic.co/t/management-of-illegal-characters/377159/9 "2025-04-15T23:46:18Z")

</div>

You could parse it using a [date](https://www.elastic.co/docs/reference/logstash/plugins/plugins-filters-date) filter. I believe that will get sent to elasticsearch in an acceptable format.

If not, you can reformat it using ruby. See [this](https://discuss.elastic.co/t/date-field-being-converted-to-timestamps/180044/4) thread.

You could also reformat it using a more complex gsub, but that doesn't feel right to me.

```
mutate { gsub => ["someField", "(\d{2})/(\d{2})/(\d{4}) (\d{2}:\d{2}:\d{2}):(\d{3})", "\3/\1/\2 \4.\5"] }

```

Just looking at that makes my eyes bleed!

---

_[View the full topic](https://discuss.elastic.co/t/management-of-illegal-characters/377159)._
