# Mutate gsub json with backslash

**URL:** <https://discuss.elastic.co/t/mutate-gsub-json-with-backslash/176981>\
**Category:** Logstash\
**Created:** [April 15, 2019, 10:37pm UTC](https://discuss.elastic.co/t/mutate-gsub-json-with-backslash/176981 "2019-04-15T22:37:52Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![stash2logs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stash2logs/32/42101_2.png) [@stash2logs](https://discuss.elastic.co/u/stash2logs)\
**Post date:** [April 15, 2019, 10:37pm UTC](https://discuss.elastic.co/t/mutate-gsub-json-with-backslash/176981/1 "2019-04-15T22:37:52Z")

</div>

{\n"protocol":"HTTP/1.1",\n"remote\_addr":"127.0.0.1"}

I have the follwing json message and I'm looking to use the mutate gsub filter to do two things:  
1 - remove the \n  
2 - remove the \ (backslashes)

Ideally i would like to get the following format:  
{"protocol":"HTTP/1.1","remote\_addr":"127.0.0.1"}

It seems like the mutate gsub is not working as expected on serialized json... Here is a snippet of my logstash.conf

```
json{
          source => "message"
          target => "parsedJson"
          remove_field=>["message"]
       }
       if [parsedJson][logger_name] == "com.test" {
           mutate{
              gsub => ["[parsedJson][message]", "[\n]", ""]
              gsub => ["[parsedJson][message]", "[\\]", ""]
           }
           json {
             source => "message"
             target => "newmessage"
           }
       }
}

```

Here is the event output  
{  
"@version" =\> "1",  
"path" =\> "/test/api-logstash.log",  
"parsedJson" =\> {  
"logger\_name" =\> "com.test",  
"level" =\> "INFO",  
"@version" =\> 1,  
"thread\_name" =\> "dw-29",  
"level\_value" =\> 20000,  
"@timestamp" =\> "2019-04-15T18:34:49.679-04:00",  
"message" =\> "{"protocol":"HTTP/1.1","remote\_addr":"127.0.0.1"}"  
},  
"host" =\> "myserver",  
"@timestamp" =\> 2019-04-15T22:34:50.465Z  
}

As you can see the newline is removed but the backslashes are still there. Any idea on how to achieve this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 15, 2019, 11:52pm UTC](https://discuss.elastic.co/t/mutate-gsub-json-with-backslash/176981/2 "2019-04-15T23:52:43Z")

</div>

In your second json filter you want to replace message with [parsedJson][message].

I was very surprised to find that your mutate works for me.

```
input { generator { count => 1 message => 'foo
bar\baz' } }

```

gets me

```
   "message" => "foo\nbar\\baz",

```

and if I add

```
filter {
    mutate{
        gsub => ["[message]", "[\n]", ""]
        gsub => ["[message]", "[\\]", ""]
    }
}

```

that is reduced to

```
   "message" => "foobarbaz",

```

I would expect to have to use a literal newline in the character group

```
filter {
    mutate{
        gsub => ["[message]", "[\\
]", ""]
    }
}
```

---

<div class="post-metadata">

**Author:** ![stash2logs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stash2logs/32/42101_2.png) [@stash2logs](https://discuss.elastic.co/u/stash2logs)\
**Post date:** [April 16, 2019, 12:07am UTC](https://discuss.elastic.co/t/mutate-gsub-json-with-backslash/176981/3 "2019-04-16T00:07:09Z")

</div>

Did you try running that same filter on a test JSON? It does not work as expected.  
Try it on this JSON  
{\n"protocol":"HTTP/1.1",\n"remote\_addr":"127.0.0.1"}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 16, 2019, 12:38am UTC](https://discuss.elastic.co/t/mutate-gsub-json-with-backslash/176981/4 "2019-04-16T00:38:25Z")

</div>

> [@stash2logs](#):
>
> Did you try running that same filter on a test JSON? It does not work as expected.

You are not using either markdown or block-quoting on the text you want parsed.

I cannot un-parse a parser. If you show us what a message looks like then someone will help you...

---

<div class="post-metadata">

**Author:** ![stash2logs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stash2logs/32/42101_2.png) [@stash2logs](https://discuss.elastic.co/u/stash2logs)\
**Post date:** [April 16, 2019, 12:41am UTC](https://discuss.elastic.co/t/mutate-gsub-json-with-backslash/176981/5 "2019-04-16T00:41:12Z")

</div>

Here is what the message looks like:

`{\n\"protocol\":\"HTTP/1.1\",\n\"remote_addr\":\"127.0.0.1\"}`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 16, 2019, 12:30pm UTC](https://discuss.elastic.co/t/mutate-gsub-json-with-backslash/176981/6 "2019-04-16T12:30:06Z")

</div>

Please either surround your example message with lines containing just

````
```

````

or else indent it using 4 spaces. Then tell us whether that is literally what the message looks like, or whether it is the rubydebug output of the message.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2019, 12:30pm UTC](https://discuss.elastic.co/t/mutate-gsub-json-with-backslash/176981/7 "2019-05-14T12:30:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
