# Replacement across all fields with single rule

**URL:** https://discuss.elastic.co/t/replacement-across-all-fields-with-single-rule/27081
**Category:** Logstash
**Created:** [August 9, 2015, 5:04am UTC](https://discuss.elastic.co/t/replacement-across-all-fields-with-single-rule/27081 "2015-08-09T05:04:34Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![KrishnaPG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krishnapg/32/4111_2.png) [@KrishnaPG](https://discuss.elastic.co/u/KrishnaPG)
#### Post date: [August 9, 2015, 5:04am UTC](https://discuss.elastic.co/t/replacement-across-all-fields-with-single-rule/27081/1 "2015-08-09T05:04:34Z")

</div>

I have around 40 fields of numeric data in csv format and occasionally multiple fields in a row could be invalid values (indicated with, say, hyphen **-** ).

In the logstash is there a way to define a single generic mutate rule that works on all the fields to convert the hyphen ( **-** ) into numeric zero ( **0** ).

Right now, I have to have mutate rule once for each field, which is not really good way. For example,

```
csv { columns => [col1, col2, col3, .... col40] }
mutate {
gsub => [
    "col1", "-", 0,
    "col2", "- ", 0,
     ....
   ]
 }
}

```

Is there a much better simpler way to achieve this than to manually specify the same rule 40 times?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 9, 2015, 7:41am UTC](https://discuss.elastic.co/t/replacement-across-all-fields-with-single-rule/27081/2 "2015-08-09T07:41:10Z")

</div>

You'd have to use a [ruby filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html). Untested example:

```
filter {
  ruby {
    code => '
      event.to_hash.each { |k, v|
        event[k] = 0 if v == "-"
      }
    '
  }
}

```

---

<div class="post-metadata">

### Author: ![KrishnaPG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krishnapg/32/4111_2.png) [@KrishnaPG](https://discuss.elastic.co/u/KrishnaPG)
#### Post date: [August 9, 2015, 11:39am UTC](https://discuss.elastic.co/t/replacement-across-all-fields-with-single-rule/27081/3 "2015-08-09T11:39:59Z")

</div>

Thanks @magnusbaeck I am not familiar with Ruby. Will try to look into it.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:32am UTC](https://discuss.elastic.co/t/replacement-across-all-fields-with-single-rule/27081/4 "2017-07-06T05:32:31Z")

</div>


