# Removing backslashes (\\)

**URL:** <https://discuss.elastic.co/t/removing-backslashes/338828>\
**Category:** Kibana\
**Tags:** painless\
**Created:** [July 19, 2023, 8:58pm UTC](https://discuss.elastic.co/t/removing-backslashes/338828 "2023-07-19T20:58:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![CodeMonky](https://avatars.discourse-cdn.com/v4/letter/c/ecccb3/32.png) [@CodeMonky](https://discuss.elastic.co/u/CodeMonky)\
**Post date:** [July 19, 2023, 8:58pm UTC](https://discuss.elastic.co/t/removing-backslashes/338828/1 "2023-07-19T20:58:09Z")

</div>

Good day all!

I have log files that I'm trying to ingest into a test pipeline. I have my grok patterns and everything but when I run the pipeline it fails. I believe it is failing due to the logs having back-slashes in the log.

Ex: subtype="ips" eventtype="signature" level="alert" vd="root" etc

I'm trying to use the Script Processor with the following script:

```auto
PUT _ingest/pipeline/Test2
{
  "description": "Updated pipeline with changes",
  "processors": [
    {
      "script": {
        "lang": "painless",
        "source": "ctx.temp = ctx.temp.replaceAll('\\\\\\\\', '').replaceAll('\\\\', '')"
      }
    }
  ]
}

```

When I run the processor, it keeps getting a compile error and I'm not sure where. My one clue is this:

 ![Screenshot 2023-07-19 165455](https://us1.discourse-cdn.com/elastic/original/3X/d/9/d9fcd5b50ed0d65ce2087d813c785c78ec3f1041.png)

But I can't get a real answer on WHY this is wrong. Any Ideas?

Note that I'm using GREEDYDATA to hold everything past the first few pattern parts in a location called temp, which is why you'll see that "temp" used in the script.

Grok: %{MONTH:month} %{MONTHDAY:day} %{TIME:time} %{WORD:device} %{GREEDYDATA:temp}

Thanks!

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [July 20, 2023, 2:16pm UTC](https://discuss.elastic.co/t/removing-backslashes/338828/2 "2023-07-20T14:16:45Z")

</div>

Hi @CodeMonky, welcome to our community. You posted something that is more suited to the [Elasticsearch forum](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6) (nothing specific about Kibana in your question).

Have you experimented just with the pipeline with the `simulate` endpoint to isolate the script?

I ran this super simple test in the Dev Console using the [`gsub`](https://www.elastic.co/guide/en/elasticsearch/reference/current/gsub-processor.html) processor instead, and it is working well for the tests documents I passed:

```auto
POST /_ingest/pipeline/_simulate
{
  "pipeline" :
  {
    "description": "_description",
    "processors": [
      {
        "gsub": {
          "field" : "temp",
          "pattern" : "\\\\",
          "replacement": ""
        }
      }
    ]
  },
  "docs": [
    {
      "_index": "index",
      "_id": "id",
      "_source": {
        "temp": "bar"
      }
    },
    {
      "_index": "index",
      "_id": "id",
      "_source": {
        "temp": "\\this has \\back \\slashes"
      }
    },
    {
      "_index": "index",
      "_id": "id",
      "_source": {
        "temp": "-\\-\\\\-\\-"
      }
    }
  ]
}

```

Resulting with:

```auto
{
  "docs": [
    {
      "doc": {
        "_index": "index",
        "_id": "id",
        "_version": "-3",
        "_source": {
          "temp": "bar"
        },
        "_ingest": {
          "timestamp": "2023-07-20T14:12:56.75455216Z"
        }
      }
    },
    {
      "doc": {
        "_index": "index",
        "_id": "id",
        "_version": "-3",
        "_source": {
          "temp": "this has back slashes"
        },
        "_ingest": {
          "timestamp": "2023-07-20T14:12:56.754585461Z"
        }
      }
    },
    {
      "doc": {
        "_index": "index",
        "_id": "id",
        "_version": "-3",
        "_source": {
          "temp": "----"
        },
        "_ingest": {
          "timestamp": "2023-07-20T14:12:56.754639162Z"
        }
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2023, 2:16pm UTC](https://discuss.elastic.co/t/removing-backslashes/338828/3 "2023-08-17T14:16:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
