# Remove single quotes from a string

**URL:** <https://discuss.elastic.co/t/remove-single-quotes-from-a-string/272863>\
**Category:** Logstash\
**Created:** [May 12, 2021, 11:25pm UTC](https://discuss.elastic.co/t/remove-single-quotes-from-a-string/272863 "2021-05-12T23:25:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![daniel\_a](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_a/32/48390_2.png) [@daniel\_a](https://discuss.elastic.co/u/daniel_a)\
**Post date:** [May 12, 2021, 11:25pm UTC](https://discuss.elastic.co/t/remove-single-quotes-from-a-string/272863/1 "2021-05-12T23:25:32Z")

</div>

How do I remove single quotes from the message field using Logstash **gsub** filter? I've tried the syntax below, and it didn't work.

```
  mutate {
    gsub => ["[message]", "'", "" ] 
  }

  mutate {
    gsub => ["[message]", "\\'", "" ] 
  }

```

Example:

```
{ "description": "These are just random users' credentials." }

```

In the example above, the single quote is right after the word **users**. I just want to remove it, I don't need to replace it with anything else.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 12, 2021, 11:34pm UTC](https://discuss.elastic.co/t/remove-single-quotes-from-a-string/272863/2 "2021-05-12T23:34:38Z")

</div>

```
mutate { gsub => ["[message]", "'", "" ] }

```

is the way to do it.

---

<div class="post-metadata">

**Author:** ![daniel\_a](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_a/32/48390_2.png) [@daniel\_a](https://discuss.elastic.co/u/daniel_a)\
**Post date:** [May 13, 2021, 12:31am UTC](https://discuss.elastic.co/t/remove-single-quotes-from-a-string/272863/3 "2021-05-13T00:31:26Z")

</div>

I was thinking the same, but I'm still getting an error.

This is the input/filter code.

```
input {
  generator {
    lines => [
      '{ "description": "These are just random users' credentials." }'
    ]
    count => 1
  }
}

filter {
  mutate {
    gsub => ["[message]", "'", "" ] 
  }

```

Error:

```
[2021-05-03T04:30:41,717][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"{\", \",\", \"]\" at line 4, column 55 (byte 92) after input {\n generator {\n lines => [\n '{ \"description\": \"These are just random users' ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:184:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:69:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:365:in `block in converge_state'"]}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 13, 2021, 12:45am UTC](https://discuss.elastic.co/t/remove-single-quotes-from-a-string/272863/4 "2021-05-13T00:45:09Z")

</div>

> [@daniel\_a](#):
>
> `'{ "description": "These are just random users' credentials." }'`

The ' after users is closing out the ' at the start of the line, you need to escape it.

---

<div class="post-metadata">

**Author:** ![daniel\_a](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_a/32/48390_2.png) [@daniel\_a](https://discuss.elastic.co/u/daniel_a)\
**Post date:** [May 13, 2021, 1:14am UTC](https://discuss.elastic.co/t/remove-single-quotes-from-a-string/272863/5 "2021-05-13T01:14:44Z")

</div>

This makes sense now. It seems it's just harder to test this with the generator. I should be all good when I'm ready to pull logs via its primary method, logs won't be wrapped with single quotes.

Thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 13, 2021, 1:48am UTC](https://discuss.elastic.co/t/remove-single-quotes-from-a-string/272863/6 "2021-05-13T01:48:37Z")

</div>

I use a generator input a lot for testing things, but sometimes it is easier to put a line in a file, set sincedb\_path to /dev/null, and use `--config.reload.automatic` to re-read the file every time you edit the configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2021, 1:49am UTC](https://discuss.elastic.co/t/remove-single-quotes-from-a-string/272863/7 "2021-06-10T01:49:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
