# Remove opening and closing parenthesis using gsub

**URL:** <https://discuss.elastic.co/t/remove-opening-and-closing-parenthesis-using-gsub/317100>\
**Category:** Logstash\
**Created:** [October 20, 2022, 10:49am UTC](https://discuss.elastic.co/t/remove-opening-and-closing-parenthesis-using-gsub/317100 "2022-10-20T10:49:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ombit](https://avatars.discourse-cdn.com/v4/letter/o/ea5d25/32.png) [@ombit](https://discuss.elastic.co/u/ombit)\
**Post date:** [October 20, 2022, 10:49am UTC](https://discuss.elastic.co/t/remove-opening-and-closing-parenthesis-using-gsub/317100/1 "2022-10-20T10:49:50Z")

</div>

Hi all,

I am using Logstash to change the formatting of messages before forwarding them on to a QRadar reader.

The syslogs are coming from various other servers, being collated onto one central 'master' server within one file which is being watched by Filebeat for logstash to convert and send on. This is all working now, so thank you to those that helped me.

I've now heard that this has exposed a new issue, in that some of the original hosts of the syslogs are surrounded by parenthesis and I now need to remove them.

So my message may look like:

Oct 12 08:00:00 (iamservera) message

How do I remove the parenthesis using gsub? My efforts so far are failing.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 20, 2022, 12:21pm UTC](https://discuss.elastic.co/t/remove-opening-and-closing-parenthesis-using-gsub/317100/2 "2022-10-20T12:21:54Z")

</div>

`mutate{ gsub => ["message", "[()]", ""] }`

```auto
{
         "event" => {
        "original" => "Oct 12 08:00:00 (iamservera) message"
    },
       "message" => "Oct 12 08:00:00 iamservera message"
}

```

---

<div class="post-metadata">

**Author:** ![ombit](https://avatars.discourse-cdn.com/v4/letter/o/ea5d25/32.png) [@ombit](https://discuss.elastic.co/u/ombit)\
**Post date:** [October 20, 2022, 1:01pm UTC](https://discuss.elastic.co/t/remove-opening-and-closing-parenthesis-using-gsub/317100/3 "2022-10-20T13:01:44Z")

</div>

> [@Rios](#):
>
> mutate{ gsub =\> ["message", "[()]", ""] }

Sadly, it's not removing them:

```auto
        mutate {
            gsub => ["message", "[()]", "" ]
            }

```

`Syslog message: (unknown): Oct 20 12:55:51 (iamservera) **.**.*.**->/var/log/evtmgr_statuslog charon stat : ONLINE\n`

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 20, 2022, 1:04pm UTC](https://discuss.elastic.co/t/remove-opening-and-closing-parenthesis-using-gsub/317100/4 "2022-10-20T13:04:23Z")

</div>

Can you share your Logstash pipeline?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 20, 2022, 1:23pm UTC](https://discuss.elastic.co/t/remove-opening-and-closing-parenthesis-using-gsub/317100/5 "2022-10-20T13:23:21Z")

</div>

Something is not OK. This conf is working fine. Can you test the same?

```auto
input {
  generator {
       "message" => "Syslog message: (unknown): Oct 20 12:55:51 (iamservera) **.**.*.**->/var/log/evtmgr_statuslog charon stat : ONLINE\n"
       count => 1
  }
 
} # input

filter {

 	mutate{ gsub => ["message", "[()]", ""] }
   
}

output {

    stdout {
        codec => rubydebug{ metadata => true}
    }

}

```

Result:

```auto
{
         "event" => {
        "original" => "Syslog message: (unknown): Oct 20 12:55:51 (iamservera) **.**.*.**->/var/log/evtmgr_statuslog charon stat : ONLINE\\n"
    },
       "message" => "Syslog message: unknown: Oct 20 12:55:51 iamservera **.**.*.**->/var/log/evtmgr_statuslog charon stat : ONLINE\\n"
}

```

---

<div class="post-metadata">

**Author:** ![ombit](https://avatars.discourse-cdn.com/v4/letter/o/ea5d25/32.png) [@ombit](https://discuss.elastic.co/u/ombit)\
**Post date:** [October 21, 2022, 8:17am UTC](https://discuss.elastic.co/t/remove-opening-and-closing-parenthesis-using-gsub/317100/6 "2022-10-21T08:17:41Z")

</div>

Please accept my apologies, for some reason my pipeline.conf had not saved (which was masked from me due to puppet).

Your solutions have worked - so thank you so very much as always. This really is a great community group.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 21, 2022, 9:51am UTC](https://discuss.elastic.co/t/remove-opening-and-closing-parenthesis-using-gsub/317100/7 "2022-10-21T09:51:47Z")

</div>

Long live the king and the Elastic team.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2022, 9:51am UTC](https://discuss.elastic.co/t/remove-opening-and-closing-parenthesis-using-gsub/317100/8 "2022-11-18T09:51:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
