# Removing non-numeric characters from a field not working in logstash

**URL:** <https://discuss.elastic.co/t/removing-non-numeric-characters-from-a-field-not-working-in-logstash/296648>\
**Category:** Logstash\
**Created:** [February 8, 2022, 6:14pm UTC](https://discuss.elastic.co/t/removing-non-numeric-characters-from-a-field-not-working-in-logstash/296648 "2022-02-08T18:14:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![curiousmind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/curiousmind/32/69452_2.png) [@curiousmind](https://discuss.elastic.co/u/curiousmind)\
**Post date:** [February 8, 2022, 6:14pm UTC](https://discuss.elastic.co/t/removing-non-numeric-characters-from-a-field-not-working-in-logstash/296648/1 "2022-02-08T18:14:12Z")

</div>

need an urgent help.I am getting this error

```auto
[2022-02-08T18:25:01,995][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>"xjmdwt2/wbqlYsoFmJO31KfAC/s=", :_index=>"logs-prod-2022.02.08", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x735783ad>], :response=>{"index"=>{"_index"=>"logs-prod-2022.02.08", "_type"=>"_doc", "_id"=>"xjmdwt2/wbqlYsoFmJO31KfAC/s=", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [session.in.packet] of type [long] in document with id 'xjmdwt2/wbqlYsoFmJO31KfAC/s='. Preview of field's value: '1\n'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"For input string: \"1\n\"" }}}}}

```

I am doing the below mutate in my config, so as to remove all the non-digit words. But still, why do I get the above error?

```auto
 mutate {
          gsub => ["[session][in][packet]", "\D", "" ]
        }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 8, 2022, 6:49pm UTC](https://discuss.elastic.co/t/removing-non-numeric-characters-from-a-field-not-working-in-logstash/296648/2 "2022-02-08T18:49:42Z")

</div>

gsub does not do a multiline match by default. I do not know if it is possible to enable it.

```
input { generator { count => 1 lines => [ '1
' ] } }
filter {
    ruby { code => 'event.set("message", event.get("message").gsub(/\D/m, ""))' }
}

```

Changes `"1\n"` to `"1"`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2022, 6:50pm UTC](https://discuss.elastic.co/t/removing-non-numeric-characters-from-a-field-not-working-in-logstash/296648/3 "2022-03-08T18:50:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
