# Remove garbage from message end

**URL:** <https://discuss.elastic.co/t/remove-garbage-from-message-end/263916>\
**Category:** Logstash\
**Created:** [February 10, 2021, 6:14pm UTC](https://discuss.elastic.co/t/remove-garbage-from-message-end/263916 "2021-02-10T18:14:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_smith/32/79638_2.png) [@John\_Smith](https://discuss.elastic.co/u/John_Smith)\
**Post date:** [February 10, 2021, 6:14pm UTC](https://discuss.elastic.co/t/remove-garbage-from-message-end/263916/1 "2021-02-10T18:14:03Z")

</div>

Hello,

I've following message send by filebeat:  
"message" =\> "{"country-code":"GB","payload":"{\"access\_token\":\"\*\*\*\*\*\*\*\*\*\*\",\"token\_type\":\"Bearer\",}","status":"ok","status-code":200,"error":"","content-type":"application/x-www-form-urlencoded","inbound-request-uri":"","outbound-url":"","message-size":106,"msisdn":"","env-name":"staging","headers":{"Connection":"keep-alive","Content-Type":"application/json"},"service-flow":"PreFlow","verb":"POST"}\u0000"

For some reason filebeat put this \u0000 at the end of the message - why i think it's filebeat - because for now we're using rsyslog and this is not there . I'm trying to switch to filebeat.

So this (\u0000) breaking next filter  
json {  
source message  
}

Can someone advice how to remove this garbage ?  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 10, 2021, 6:17pm UTC](https://discuss.elastic.co/t/remove-garbage-from-message-end/263916/2 "2021-02-10T18:17:25Z")

</div>

Try

```
mutate { gsub => ["message", "\u0000", ""] }

```

If that does not work then send the event to

```
output { stdout { codec => rubydebug } }

```

and show us what that \u0000 looks like.

---

<div class="post-metadata">

**Author:** ![John\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/john_smith/32/79638_2.png) [@John\_Smith](https://discuss.elastic.co/u/John_Smith)\
**Post date:** [February 10, 2021, 11:07pm UTC](https://discuss.elastic.co/t/remove-garbage-from-message-end/263916/3 "2021-02-10T23:07:25Z")

</div>

Thanks Badger,

It's working, but is there any solution to check if it's exactly at the end of the message field - don't want to drop something inside ?

Thanks again.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 10, 2021, 11:19pm UTC](https://discuss.elastic.co/t/remove-garbage-from-message-end/263916/4 "2021-02-10T23:19:13Z")

</div>

You can anchor it using $ so that it only matches at the end of the string...

```
mutate { gsub => ["message", "\u0000$", ""] }`
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2021, 11:19pm UTC](https://discuss.elastic.co/t/remove-garbage-from-message-end/263916/5 "2021-03-10T23:19:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
