# Pre-process message backslashes prior to JSON filter

**URL:** <https://discuss.elastic.co/t/pre-process-message-backslashes-prior-to-json-filter/169821>\
**Category:** Logstash\
**Created:** [February 25, 2019, 11:59am UTC](https://discuss.elastic.co/t/pre-process-message-backslashes-prior-to-json-filter/169821 "2019-02-25T11:59:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![NathanBaulch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathanbaulch/32/19785_2.png) [@NathanBaulch](https://discuss.elastic.co/u/NathanBaulch)\
**Post date:** [February 25, 2019, 11:59am UTC](https://discuss.elastic.co/t/pre-process-message-backslashes-prior-to-json-filter/169821/1 "2019-02-25T11:59:49Z")

</div>

I'm trying to replace the literal string "\x" with "\u00" just before parsing JSON to (somewhat naively) convert invalid hex escapes (coming from Nginx) into Unicode escapes. However no matter what I try I always get `LogStash::Json::ParserError: Unexpected character ('\' (code 92)): was expecting double-quote to start field name`.

My filter:

```auto
filter {
  mutate { gsub => ["message", "\\x", "\\u00"] }
  json { source => "message" }
}

```

I've tried every combination of single, double and quadruple backslash in the regex pattern and replace values but no luck. Where am I going wrong?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 25, 2019, 1:09pm UTC](https://discuss.elastic.co/t/pre-process-message-backslashes-prior-to-json-filter/169821/2 "2019-02-25T13:09:01Z")

</div>

Does [config.support\_escapes](https://www.elastic.co/guide/en/logstash/current/logstash-settings-file.html) work for you?

---

<div class="post-metadata">

**Author:** ![NathanBaulch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathanbaulch/32/19785_2.png) [@NathanBaulch](https://discuss.elastic.co/u/NathanBaulch)\
**Post date:** [February 26, 2019, 12:47am UTC](https://discuss.elastic.co/t/pre-process-message-backslashes-prior-to-json-filter/169821/3 "2019-02-26T00:47:31Z")

</div>

No change unfortunately. The only difference is I had to use quadruple backslash in my filter definition above, which makes sense.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 26, 2019, 1:30am UTC](https://discuss.elastic.co/t/pre-process-message-backslashes-prior-to-json-filter/169821/4 "2019-02-26T01:30:32Z")

</div>

I believe the intent of that option was the opposite, so that you could use single backslashes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 26, 2019, 1:34am UTC](https://discuss.elastic.co/t/pre-process-message-backslashes-prior-to-json-filter/169821/5 "2019-03-26T01:34:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
