# Replacing Special Characters

**URL:** <https://discuss.elastic.co/t/replacing-special-characters/123254>\
**Category:** Logstash\
**Created:** [March 9, 2018, 11:26am UTC](https://discuss.elastic.co/t/replacing-special-characters/123254 "2018-03-09T11:26:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![phillipgibb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phillipgibb/32/14307_2.png) [@phillipgibb](https://discuss.elastic.co/u/phillipgibb)\
**Post date:** [March 9, 2018, 11:26am UTC](https://discuss.elastic.co/t/replacing-special-characters/123254/1 "2018-03-09T11:26:30Z")

</div>

Hi,

I have a filter with:

mutate {  
gsub =\> [  
"message", "\u003e", "\>",  
"message", "\u003c", "\<",  
"message", "[\n]", "",  
"message", "\"", "'"  
]  
}

that I apply to :  
{"log":"screen=None callback\_url='/api' request\_type='sms' handler="\u003cclass 'Entrypoint'\u003e" event='entry\_point\_handler'\n","stream":"stdout","time":"2018-03-09T07:39:59.580260866Z"}

the mutate does not get applied in fact in the logstash output I see that message is now:  
{\"log\":\"screen=None callback\_url='/api' request\_type='sms' handler=\"\\u003cclass 'Entrypoint'\\u003e\" event='entry\_point\_handler'\\n",\"stream":\"stdout",\"time":\"2018-03-09T07:39:59.580260866Z\"}

even worse.

What I really want to do is get rid of the special character because it seems to be what is stopping the json plugin from working

thanks

Phill

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2018, 11:26am UTC](https://discuss.elastic.co/t/replacing-special-characters/123254/2 "2018-04-06T11:26:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
