# Null terminated message string

**URL:** <https://discuss.elastic.co/t/null-terminated-message-string/315905>\
**Category:** Logstash\
**Created:** [October 5, 2022, 6:27pm UTC](https://discuss.elastic.co/t/null-terminated-message-string/315905 "2022-10-05T18:27:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![LisaJ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lisaj/32/108271_2.png) [@LisaJ](https://discuss.elastic.co/u/LisaJ)\
**Post date:** [October 5, 2022, 6:27pm UTC](https://discuss.elastic.co/t/null-terminated-message-string/315905/1 "2022-10-05T18:27:04Z")

</div>

I have a syslog message that contains a null terminated string: `"syslog_message":"A10\u0000"` -- these messages represent is-alive checks from a load balancer to the logstash servers. I would prefer not to have thousands of "the A10 checked & said logstash is still there" filling up Elasticsearch.

I've been able to filter out any messages that _start with_ A10. Since our "real" messages , I shouldn't be dropping any good data, but I wonder if there is there any way to do an exact match for the full string including the null termination character. I've commented out the ones I've tried that _haven't_ worked.

```auto
    #if [message] == "A10\u0000"{
    #if [message] == "A10\\u0000"{
    #if [message] == 'A10\u0000'{
    if [message] =~ /^A10/{
       drop { }
    }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 5, 2022, 6:56pm UTC](https://discuss.elastic.co/t/null-terminated-message-string/315905/2 "2022-10-05T18:56:04Z")

</div>

As far as I know the logstash configuration does not recognize Unicode escape sequences. They are taken literally. Normally I would suggest inserting the actual character, but I do not think that will work with NUL.

You could drop anything that has A10 followed by a single character using

```
if [message] =~ "^A10.$" { drop {} }

```

If you really want to check for NUL then I think you would have to use a ruby filter and call event.cancel if it matches.

---

<div class="post-metadata">

**Author:** ![LisaJ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lisaj/32/108271_2.png) [@LisaJ](https://discuss.elastic.co/u/LisaJ)\
**Post date:** [October 5, 2022, 6:59pm UTC](https://discuss.elastic.co/t/null-terminated-message-string/315905/3 "2022-10-05T18:59:57Z")

</div>

Thanks for the suggestion -- the odds of a false positive on your /^A10.$/ regex is sufficiently low that it's not worth sorting out anything more exact.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2022, 7:00pm UTC](https://discuss.elastic.co/t/null-terminated-message-string/315905/4 "2022-11-02T19:00:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
