# Remove backslash from xml log

**URL:** <https://discuss.elastic.co/t/remove-backslash-from-xml-log/315891>\
**Category:** Logstash\
**Created:** [October 5, 2022, 2:46pm UTC](https://discuss.elastic.co/t/remove-backslash-from-xml-log/315891 "2022-10-05T14:46:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jathurshan\_Sumandira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jathurshan_sumandira/32/108118_2.png) [@Jathurshan\_Sumandira](https://discuss.elastic.co/u/Jathurshan_Sumandira)\
**Post date:** [October 5, 2022, 2:46pm UTC](https://discuss.elastic.co/t/remove-backslash-from-xml-log/315891/1 "2022-10-05T14:46:45Z")

</div>

\<soap-env:envelope xmlns:soap-env=\"........ \" xmlns:m2=\".... \".........................\</soap-env:envelope\>

I wanted to remove the backslashs ("\") in above xml log-line and I have tried

ruby {  
code =\> ' d= event.get("logMsg");  
d = d. gsub("\\", " ");'  
}

But, my code does not work, it does not remove the backslashs. If anyone who knows the solution please help me.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 5, 2022, 4:27pm UTC](https://discuss.elastic.co/t/remove-backslash-from-xml-log/315891/2 "2022-10-05T16:27:37Z")

</div>

Add:

```auto
mutate {
  gsub => ["logMsg","[\\]",""]
}

```

---

<div class="post-metadata">

**Author:** ![Jathurshan\_Sumandira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jathurshan_sumandira/32/108118_2.png) [@Jathurshan\_Sumandira](https://discuss.elastic.co/u/Jathurshan_Sumandira)\
**Post date:** [October 6, 2022, 5:09am UTC](https://discuss.elastic.co/t/remove-backslash-from-xml-log/315891/3 "2022-10-06T05:09:56Z")

</div>

Hi, @Rios Thanks for you reply. Unfortunately, this does not work for my case, it does not remove backslash in the xml tags.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 6, 2022, 7:48am UTC](https://discuss.elastic.co/t/remove-backslash-from-xml-log/315891/4 "2022-10-06T07:48:54Z")

</div>

In your case it's related to quotes not to backslash. Strings are always displayed under quotes. How you will display quotes inside string except with backslash+quote  
In general, if you remove \ from the string, use next code:

```auto
	mutate {
  add_field => { "dir" => "c:\temp\test.txt" }
	}
	mutate {
		gsub => ["dir","[\\]",""]
	}

```

The result would be:

```auto
"dir" => "c:temptest.txt"

```

There is a workaround for your case, replace double quotes with single quotes, XML will be still valid. I have tested in [XMLViewer](https://codebeautify.org/xmlviewer)

```auto
mutate {
  gsub => ["temp",'[\"]',"'"]
}

```

For instance:  
`"<?xml version=\"1.0\"?><catalog><book id=\"bk101\"><author>Gambardella, Matthew</author><title>XML Developer's Guide</title></book><book id=\"bk102\"><author>Ralls, Kim</author><title>Midnight Rain</title></book></catalog>"`

Will change in:

```auto
<?xml version='1.0'?><catalog><book id='bk101'><author>Gambardella, Matthew</author><title>XML Developer's Guide</title></book><book id='bk102'><author>Ralls, Kim</author><title>Midnight Rain</title></book></catalog>

```

However I wouldn't do any changes.

Badger, do you have any better idea?

---

<div class="post-metadata">

**Author:** ![Jathurshan\_Sumandira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jathurshan_sumandira/32/108118_2.png) [@Jathurshan\_Sumandira](https://discuss.elastic.co/u/Jathurshan_Sumandira)\
**Post date:** [October 6, 2022, 12:32pm UTC](https://discuss.elastic.co/t/remove-backslash-from-xml-log/315891/5 "2022-10-06T12:32:39Z")

</div>

Thank you for the solution. It worked for me.

But need to extract some data from xml because of single quote it does not take it as a xml in to find the [XPATH](http://xpather.com/) again I wanted to replace the single quotes with double quotes

Need result like as below with double quotes

`<?xml version="1.0"?><catalog><book id="bk101"><author>Gambardella, Matthew</author><title>XML Developer"s Guide</title></book><book id="bk102"><author>Ralls, Kim</author><title>Midnight Rain</title></book></catalog>`

Thanks in Advanced

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2022, 12:33pm UTC](https://discuss.elastic.co/t/remove-backslash-from-xml-log/315891/6 "2022-11-03T12:33:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
