# Replace my \\r\\n with a new line using mutate gsub

**URL:** <https://discuss.elastic.co/t/replace-my-r-n-with-a-new-line-using-mutate-gsub/288240>\
**Category:** Logstash\
**Created:** [November 2, 2021, 3:25pm UTC](https://discuss.elastic.co/t/replace-my-r-n-with-a-new-line-using-mutate-gsub/288240 "2021-11-02T15:25:52Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [November 2, 2021, 3:25pm UTC](https://discuss.elastic.co/t/replace-my-r-n-with-a-new-line-using-mutate-gsub/288240/1 "2021-11-02T15:25:52Z")

</div>

Hi All

I have a csv data in this format

> {  
> "message" : "value1,value2,value3\r\nvalue4,value5,value6"  
> }

My expected result is

> {  
> "message" : "value1,value2,value3  
> value4,value5,value6"  
> }

I have tried mutate gsub, but it does not work

```auto
 mutate { gsub => [ 'message', '\r\n', '
'] }

```

It gives me again same \n. how to make this work?  
Finally i want to use csv filter and convert everything to json. But csv filter should have new line data

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 2, 2021, 4:05pm UTC](https://discuss.elastic.co/t/replace-my-r-n-with-a-new-line-using-mutate-gsub/288240/2 "2021-11-02T16:05:29Z")

</div>

What are you using to view the result? If you use rubydebug then a literal newline character will be displayed as \n, not as a newline. The same is true of some other tools.

---

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [November 2, 2021, 5:21pm UTC](https://discuss.elastic.co/t/replace-my-r-n-with-a-new-line-using-mutate-gsub/288240/3 "2021-11-02T17:21:34Z")

</div>

Hi @Badger thanks for your reply. With rubydebug i get value as `\\n`  
There is double backslash and this is not working with csv filter

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 2, 2021, 5:28pm UTC](https://discuss.elastic.co/t/replace-my-r-n-with-a-new-line-using-mutate-gsub/288240/4 "2021-11-02T17:28:10Z")

</div>

Do you actually have \r\n in your message or just \n? Perhaps you need

```auto
mutate { gsub => ['message', '[\r\n]', '
'] }

```

---

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [November 2, 2021, 5:35pm UTC](https://discuss.elastic.co/t/replace-my-r-n-with-a-new-line-using-mutate-gsub/288240/5 "2021-11-02T17:35:30Z")

</div>

Hi @Badger .This didn't work, after applying csv filter it reads only the last record/last line.Do you have any idea why it is reading only one line

I have csv data with 50K records. So i do not want to use split filter as well. Because split filter takes lot of time  
If this works i can straight use csv filter

---

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [November 2, 2021, 8:57pm UTC](https://discuss.elastic.co/t/replace-my-r-n-with-a-new-line-using-mutate-gsub/288240/6 "2021-11-02T20:57:53Z")

</div>

Hi @Badger i think its doing correct replacement of gsub, but somehow it reads only one line with csv filter. How can we fix this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 2, 2021, 9:35pm UTC](https://discuss.elastic.co/t/replace-my-r-n-with-a-new-line-using-mutate-gsub/288240/7 "2021-11-02T21:35:49Z")

</div>

If you use

```
output { stdout { codec => rubydebug } }

```

what does an event look like?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2021, 9:36pm UTC](https://discuss.elastic.co/t/replace-my-r-n-with-a-new-line-using-mutate-gsub/288240/8 "2021-11-30T21:36:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
