# Special Character as URL Params

**URL:** <https://discuss.elastic.co/t/special-character-as-url-params/72093>\
**Category:** Logstash\
**Created:** [January 18, 2017, 9:58pm UTC](https://discuss.elastic.co/t/special-character-as-url-params/72093 "2017-01-18T21:58:39Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sbruyere](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@sbruyere](https://discuss.elastic.co/u/sbruyere)\
**Post date:** [January 18, 2017, 9:58pm UTC](https://discuss.elastic.co/t/special-character-as-url-params/72093/1 "2017-01-18T21:58:39Z")

</div>

Hello,

I try tu use the following URL in a Http\_poller Input Plugin.  
url =\> "[http://10.0.10.10/login/login.cgi?mode=AUTH\_LOGIN&params=userid|password&](http://10.0.10.10/login/login.cgi?mode=AUTH_LOGIN&params=userid%7Cpassword&)"

But the special character " | " (between userid and password as params value) makes logstash to stop.

Any idea how to declare this URL in a way that Logstash takes it ?

Br,

Stephan

---

<div class="post-metadata">

**Author:** ![kopacko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kopacko/32/10733_2.png) [@kopacko](https://discuss.elastic.co/u/kopacko)\
**Post date:** [January 19, 2017, 5:27pm UTC](https://discuss.elastic.co/t/special-character-as-url-params/72093/2 "2017-01-19T17:27:33Z")

</div>

Grok Debugger is your friend. [[https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) ]

Using what you posted, I created this:

> url =\> "%{URIPROTO:protocol}://%{IP:ip\_address}%{URIPATH:url\_path}%{URIPARAM:url\_param}

Me personally, I like to split things out to as many fields as possible, especially the important ones like a username.

> url =\> "%{URIPROTO:protocol}://%{IP:ip\_address}%{URIPATH:url\_path}.\*mode=%{DATA:url\_mode}&params=%{DATA:user\_id}|%{GREEDYDATA:url\_params}&

EDIT:

Forgot the output.

> {  
> "protocol": [  
> [  
> "http"  
> ]  
> ],  
> "ip\_address": [  
> [  
> "10.0.10.10"  
> ]  
> ],  
> "IPV6": [  
> [  
> null  
> ]  
> ],  
> "IPV4": [  
> [  
> "10.0.10.10"  
> ]  
> ],  
> "url\_path": [  
> [  
> "/login/login.cgi"  
> ]  
> ],  
> "url\_mode": [  
> [  
> "AUTH\_LOGIN"  
> ]  
> ],  
> "user\_id": [  
> [  
> "userid"  
> ]  
> ],  
> "url\_params": [  
> [  
> "password"  
> ]  
> ]  
> }

---

<div class="post-metadata">

**Author:** ![sbruyere](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@sbruyere](https://discuss.elastic.co/u/sbruyere)\
**Post date:** [January 19, 2017, 9:11pm UTC](https://discuss.elastic.co/t/special-character-as-url-params/72093/3 "2017-01-19T21:11:41Z")

</div>

Hello Kopacko,

Thanks for your reply but my problem is about the URL setting of the Http\_Poller Input Plugin, not the Grog Filter Plugin.

When I give to the URL Setting a different URL it works well. As soon as I have this character " |", my logstash instance stops.

Yo,

---

<div class="post-metadata">

**Author:** ![kopacko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kopacko/32/10733_2.png) [@kopacko](https://discuss.elastic.co/u/kopacko)\
**Post date:** [January 19, 2017, 9:17pm UTC](https://discuss.elastic.co/t/special-character-as-url-params/72093/4 "2017-01-19T21:17:17Z")

</div>

Wow, haha, my bad.

I was thinking you are parsing an incoming log. Sorry about that.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 20, 2017, 6:42am UTC](https://discuss.elastic.co/t/special-character-as-url-params/72093/5 "2017-01-20T06:42:42Z")

</div>

Are there any clues in Logstash's log? Have you tried URL encoding the pipe (i.e. `%7C`)?

---

<div class="post-metadata">

**Author:** ![sbruyere](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@sbruyere](https://discuss.elastic.co/u/sbruyere)\
**Post date:** [January 21, 2017, 10:17pm UTC](https://discuss.elastic.co/t/special-character-as-url-params/72093/6 "2017-01-21T22:17:59Z")

</div>

With the vertical Bar in the Url, logstash stops with Error message : "Invalid URL".  
I've tried "...userid%7Cpassword" then the URL is issued but "%7C" is included as-is in the Request. Seen with a sniffer... %7C is not decoded.  
I've also URL encoded the entire URL then it became a invalid URL again.  
Other idea ? 🙂

---

<div class="post-metadata">

**Author:** ![sbruyere](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@sbruyere](https://discuss.elastic.co/u/sbruyere)\
**Post date:** [January 21, 2017, 10:42pm UTC](https://discuss.elastic.co/t/special-character-as-url-params/72093/7 "2017-01-21T22:42:02Z")

</div>

No OK I got it. The %7C is meant to be decoded by the server and indeed it does the job.  
Thank you very much. Sorry for the Hysteresis in my understanding 😊

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 18, 2017, 10:42pm UTC](https://discuss.elastic.co/t/special-character-as-url-params/72093/8 "2017-02-18T22:42:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
