# Proper way to escape escape characters

**URL:** <https://discuss.elastic.co/t/proper-way-to-escape-escape-characters/324143>\
**Category:** Logstash\
**Created:** [January 28, 2023, 1:02am UTC](https://discuss.elastic.co/t/proper-way-to-escape-escape-characters/324143 "2023-01-28T01:02:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hexoffender](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hexoffender/32/116449_2.png) [@hexoffender](https://discuss.elastic.co/u/hexoffender)\
**Post date:** [January 28, 2023, 1:02am UTC](https://discuss.elastic.co/t/proper-way-to-escape-escape-characters/324143/1 "2023-01-28T01:02:23Z")

</div>

Hello, I have a weird problem. I'm trying to replace `\x5c` with `\` in a mutate. However, the logstash config fails to parse when I do this:

```auto
input {
    beats {
      # The port to listen on for filebeat connections.
      port => 5044
      # The IP address to listen for filebeat connections.
      host => "localhost"
    }
}
filter {
    mutate { gsub => ["message", "\\x5C", '\\'] }
    json { source => "message" }
}
output {
    stdout { codec => rubydebug }
 }

```

Data looks like this:  
`{"test_json": "test\x5C"json\x5C"data"}`

I encounter the following error:

```auto
[ERROR] 2023-01-27 17:00:35.027 [Converge PipelineAction::Create<main>] agent - Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of \"\\\\'\", any character, \"'\" at line 20, column 1 (byte 323) after filter {\n\n mutate { gsub => [\"message\", \"\\\\x5C\", '\\\\'] }\n\n\n json { source => \"message\" }\n}\noutput {\n\n stdout { codec => rubydebug }\n }\n", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:189:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:48:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:392:in `block in converge_state'"]}

```

It seems that its escaping the `'` character causing the config to fail to parse rather than being interpreted like it should as a single `\` escape character. Is there a different way I need to escape escape characters? I find it strange I cant use a standard `\\` as an escape sequence. I've tried using odd number of escape chars like `\` or `\\\` and also with `\\\\` but it also fails to parse this configuration in either case. It seems no matter what I do it escapes the `'` or `"` in the logstash configuration file causing it to fail to parse the configuration.

Strangely enough I can just remove the binary `\x5c` with:

```auto
mutate { gsub => ["message", "\\x5C", ""] }

```

And that parses just fine. Really scratching my head on this one.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 28, 2023, 2:55am UTC](https://discuss.elastic.co/t/proper-way-to-escape-escape-characters/324143/2 "2023-01-28T02:55:01Z")

</div>

The way the logstash configuration parser works you cannot have a backslash at the end of a quoted string. It escapes the closing quote causing the parser to keep consuming your configuration as if it were part of the string, right up until the next unescaped quote or end of file.

See [here](https://discuss.elastic.co/t/cant-replace-character-with-backslash-with-gsub/287501/2) for a solution.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 28, 2023, 9:34am UTC](https://discuss.elastic.co/t/proper-way-to-escape-escape-characters/324143/3 "2023-01-28T09:34:36Z")

</div>

Why are you replacing `\x5c` with `\`? Actually it is replacement 'x5c' with nothing 🙂  
Additional problem is an improper JSON formatting.  
{"test\_json": "test\x5C"json\x5C"data"} - quotes inside quotes. Depend on source if is wrong, you can replace double " with single quotes. 2nd gsub replacement is optional.  
Try this:

```auto
input {
  generator {
       "message" => "test\x5C\"json\x5C\"data"
       count => 1
  }
}
filter {

mutate { gsub => [ "message", "x5C", "" ,
"message", '[\"]', "'",
"message","[\\]",""
] }

}
output {
    stdout { codec => rubydebug{ } }
}

```

Result

```auto
{
       "message" => "test\"json\"data",
         "event" => {
        "original" => "test\\x5C\\\"json\\x5C\\\"data"
    }
}

```

Result with '

```auto
{
       "message" => "test'json'data",
         "event" => {
        "original" => "test\\x5C\\\"json\\x5C\\\"data"
    }
}

```

---

<div class="post-metadata">

**Author:** ![hexoffender](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hexoffender/32/116449_2.png) [@hexoffender](https://discuss.elastic.co/u/hexoffender)\
**Post date:** [January 30, 2023, 5:31pm UTC](https://discuss.elastic.co/t/proper-way-to-escape-escape-characters/324143/4 "2023-01-30T17:31:18Z")

</div>

Thank you, this is the solution I needed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2023, 5:31pm UTC](https://discuss.elastic.co/t/proper-way-to-escape-escape-characters/324143/5 "2023-02-27T17:31:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
