# Mutate gsub pattern help for filter

**URL:** <https://discuss.elastic.co/t/mutate-gsub-pattern-help-for-filter/299020>\
**Category:** Logstash\
**Created:** [March 8, 2022, 12:12am UTC](https://discuss.elastic.co/t/mutate-gsub-pattern-help-for-filter/299020 "2022-03-08T00:12:12Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [March 8, 2022, 12:12am UTC](https://discuss.elastic.co/t/mutate-gsub-pattern-help-for-filter/299020/1 "2022-03-08T00:12:13Z")

</div>

Hello, still new using regular expressions I currently am working on this to parse in my "message":

{"groupByActivity":false,"exampleDevices":[{"ip":"1.2.3.4","hostname":"[example.hostname.com](http://example.hostname.com)","sid":123456,"subnet":"some-subnet","identifier":"[some-node-example.com](http://some-node-example.com)","mac":null,"did":1234}],"groupingIds":["1234"],"userTriggered":false,"activityId":"1234","externalTriggered":false,"id":"example-id","pinned":false,"title":"Possible SSL Command and Control","relatedBreaches":[{"timestamp":123456,"threatScore":123,"modelName":"Container / Unusual External Connections (example)","pbid":12345}],"details":[[{"contents":[{"type":"device","values":[{"ip":"1.2.3.4","hostname":"[example.hostname.com](http://example.hostname.com)","sid":1234,"subnet":"some-subnet","identifier":"[some-example.com](http://some-example.com)","mac":null,"did":123456}],"key":null}],"header":"Some example"}],[{"contents":[{"type":"string","values":["123b456c"],"key":"example client hash"}],"header":"Suspicious Application"},{"contents":[{"type":"timestampRange","values":[{"start":123456,"end":123456}],"key":"Time"},{"type":"externalHost","values":[{"ip":null,"hostname":"[example.com](http://example.com)"}],"key":"Endpoint"},{"type":"percentage","values":[1234],"key":"Hostname rarity"},{"type":"timestamp","values":[1234],"key":"Hostname first observed"},{"type":"externalHost","values":[{"ip":"1.2.3.4","hostname":"1.2.3.4"}],"key":"Most recent example"},{"type":"string","values":["example-test"],"key":"Most recent example"},{"type":"integer","values":[1234],"key":"Destination port"},{"type":"integer","values":[123],"key":"Connection count"},{"type":"dataVolume","values":[1234],"key":"Total data in"},{"type":"dataVolume","values":[1234],"key":"Total data out"},{"type":"string","values":["Unknown"],"key":"Validation Status"},{"type":"string","values":["Unknown"],"key":"Issuer"}],"header":"Suspicious example"}],[{"contents":[{"type":"device","values":[{"ip":"1.2.3.4","hostname":"[another-example.com](http://another-example.com)","sid":1324,"subnet":null,"identifier":"[some-example.com](http://some-example.com)","mac":null,"did":1234}],"key":null},{"type":"device","values":[{"ip":"1.2.3.4","hostname":"[one-example.com](http://one-example.com)","sid":1234,"subnet":null,"identifier":"[so-many-examples.com](http://so-many-examples.com)","mac":null,"did":1234}],"key":null},{"type":"device","values":[{"ip":"1.2.3.4","hostname":"[too-many-examples.com](http://too-many-examples.com)","sid":1234,"subnet":"12-34","identifier":"[stop-with-the-examples.com](http://stop-with-the-examples.com)","mac":null,"did":1234}],"key":null},{"type":"device","values":[{"ip":"1.2.3.4","hostname":"[wow-another-example.com](http://wow-another-example.com)","sid":1324,"subnet":null,"identifier":"[ok.example.com](http://ok.example.com)","mac":null,"did":1234}],"key":null},{"type":"device","values":[{"ip":"1.2.3.4","hostname":"[examples.i.give.up.com](http://examples.i.give.up.com)","sid":1234,"subnet":null,"identifier":"[mwhy-are-there-so-many-examples.com](http://mwhy-are-there-so-many-examples.com)","mac":null,"did":1234}],"key":null}],"header":"Other Connecting Devices Include"}]],"children":["12-34-ab-cd"],"summariser":"example\_summary","acknowledged":false,"summary":"The device some-example...\n\n stuff.","periods":[{"start":1234,"end":1234}],"attackPhases":[123],"exampleScore":23}"

it looks like the json isn't formatted correctly and the ":" is contained within the string, would a gsub replacement work? or am I going down the wrong path to solving this parsing issue?

Sorry for the bad formatting, for some odd reason the usual

```auto

```

doesn't do right trick when providing the example.

my current filter looks like this:

```auto
filter{
    json { source => "message" }
    json { source => "message" }
    mutate { gsub => ["message", "^[^{]+", "" ] }

}

```

please let me know if I can provide more to aid in help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 8, 2022, 12:40am UTC](https://discuss.elastic.co/t/mutate-gsub-pattern-help-for-filter/299020/2 "2022-03-08T00:40:21Z")

</div>

> [@itschobot](#):
>
> attackPhases":[123],"exampleScore":23}"

You have an extra " at the end of your sample data. You can fix it using

```
mutate { gsub => ["message", '"$', ""] }

```

before the json filter.

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [March 8, 2022, 4:24pm UTC](https://discuss.elastic.co/t/mutate-gsub-pattern-help-for-filter/299020/3 "2022-03-08T16:24:07Z")

</div>

> [@Badger](#):
>
> `"$`

thanks for the catch, after attempting to do another json { source =\> "message" }

it seems to not parse after group activity, I'm stuck attempting to parse that portion as well.

I added another json { source =\> "message" } but nothing happened.

Example of where it is stopping:

```auto
{\"groupByActivity\":false,
    \"exampleDevices\":[{\"ip\":\"1.2.3.4\",
        \"hostname\":\"example.hostname.com\",
        \"sid\":123456,\"subnet\":\"some-subnet\",
        \"identifier\":\"some-node-example.com\",
        \"mac\":null,

```

is it stopping because groupActivity's value is not wrapped in quotes?

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [March 8, 2022, 9:12pm UTC](https://discuss.elastic.co/t/mutate-gsub-pattern-help-for-filter/299020/4 "2022-03-08T21:12:58Z")

</div>

is it also the backslashes as well?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 8, 2022, 9:18pm UTC](https://discuss.elastic.co/t/mutate-gsub-pattern-help-for-filter/299020/5 "2022-03-08T21:18:02Z")

</div>

Hard to say, you really need to provide a reproducible example.

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [March 8, 2022, 9:30pm UTC](https://discuss.elastic.co/t/mutate-gsub-pattern-help-for-filter/299020/6 "2022-03-08T21:30:50Z")

</div>

I worked on it in vs code and what helped was getting rid of the backslashes after the auto formatting. I'm hoping that the json { source =\> "message" } works in the same fashion after getting rid of the backslashes. would it be something like this? :

```auto
mutate { gsub => ["message", "[\\]", "" ] }

```

if so, it's not working, why is that?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 8, 2022, 10:54pm UTC](https://discuss.elastic.co/t/mutate-gsub-pattern-help-for-filter/299020/7 "2022-03-08T22:54:13Z")

</div>

Again, you really need to provide a reproducible example. That mutate is the standard way to remove backslashes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2022, 10:54pm UTC](https://discuss.elastic.co/t/mutate-gsub-pattern-help-for-filter/299020/8 "2022-04-05T22:54:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
