# Using Gsub to replace field values

**URL:** <https://discuss.elastic.co/t/using-gsub-to-replace-field-values/96613>\
**Category:** Logstash\
**Created:** [August 10, 2017, 12:31pm UTC](https://discuss.elastic.co/t/using-gsub-to-replace-field-values/96613 "2017-08-10T12:31:29Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![sentinel](https://avatars.discourse-cdn.com/v4/letter/s/fbc32d/32.png) [@sentinel](https://discuss.elastic.co/u/sentinel)\
**Post date:** [August 10, 2017, 12:31pm UTC](https://discuss.elastic.co/t/using-gsub-to-replace-field-values/96613/1 "2017-08-10T12:31:29Z")

</div>

Hi

I'm trying to transform field values in order to get rid of some characters however I do not know the values.  
I tried this:  
gsub =\> ["fwdPtPrecision", ".,","."]  
but the fwdPtPrecision=0.001 was changed to 0.00. Which is not what I want . I do not want to mess with the values and I'm only aware of the characters I want to filter out.  
Can I use standard regex?

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [August 10, 2017, 1:09pm UTC](https://discuss.elastic.co/t/using-gsub-to-replace-field-values/96613/2 "2017-08-10T13:09:47Z")

</div>

Do you know what characters you are trying to get rid of? Can you give us an example. That would probably be best, your first description was kind of vague.

---

<div class="post-metadata">

**Author:** ![sentinel](https://avatars.discourse-cdn.com/v4/letter/s/fbc32d/32.png) [@sentinel](https://discuss.elastic.co/u/sentinel)\
**Post date:** [August 10, 2017, 1:31pm UTC](https://discuss.elastic.co/t/using-gsub-to-replace-field-values/96613/3 "2017-08-10T13:31:59Z")

</div>

So I have these fields with the following values

fwdPtPrecision = 0.001,  
tickCaptureEnabled = true,

And I want to get rid of the commas in the values. Simple

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [August 10, 2017, 1:33pm UTC](https://discuss.elastic.co/t/using-gsub-to-replace-field-values/96613/4 "2017-08-10T13:33:25Z")

</div>

Can you put the config file on here as well? As well as the full log example?

---

<div class="post-metadata">

**Author:** ![sentinel](https://avatars.discourse-cdn.com/v4/letter/s/fbc32d/32.png) [@sentinel](https://discuss.elastic.co/u/sentinel)\
**Post date:** [August 10, 2017, 2:08pm UTC](https://discuss.elastic.co/t/using-gsub-to-replace-field-values/96613/5 "2017-08-10T14:08:49Z")

</div>

Sorry the config is too huge to put here but here's the filter:

filter {  
mutate {  
remove\_field =\> ["unstructured\_data"]  
gsub =\> ["fwdPtPrecision", "+d,","+d"]  
}  
}

And the logs  
message:  
2017-07-13T00:13:35,878 [INFO][Client-Push:1:3][PfClientEnrichmentBlock] [BXA.ESP.2#XXX\_1#USD/CHF@lold1] BXA.ESP.2#XXX\_1#USD/CHF@lold1 client mapping resolved to ClientMappingBean{uniqueKey='BXA.ESP.2|CH02', clientRef='BXA.ESP.2', channelId='CH02', clientName='XXxx ESP 2', spotTemplateId='SPT02', throttleTemplateId='THR02', priceValidationTemplateId='PVT06', liquidityTemplateId='LET02', spotEntitlementTemplateId='SET02', fwdSpreadTemplateId='FST01', fwdEntitlementTemplateId='FET02', skewTemplateId='SKW03', tickCaptureEnabled=true, FwdSpeedBump=false, fwdPtPrecision=0.001, clientDisabled=false}  
EventType:  
PfClientEnrichmentBlock  
@timest

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [August 10, 2017, 6:46pm UTC](https://discuss.elastic.co/t/using-gsub-to-replace-field-values/96613/6 "2017-08-10T18:46:29Z")

</div>

Are you breaking these apart into separate fields or are you trying to gsub on the whole log message? Are you going to break the log message apart with groks and such? You said:

`

> So I have these fields with the following values

`

But from your configuration file these aren't separated into fields in Logstash/Elasticsearch yet.

---

<div class="post-metadata">

**Author:** ![sentinel](https://avatars.discourse-cdn.com/v4/letter/s/fbc32d/32.png) [@sentinel](https://discuss.elastic.co/u/sentinel)\
**Post date:** [August 11, 2017, 7:58am UTC](https://discuss.elastic.co/t/using-gsub-to-replace-field-values/96613/7 "2017-08-11T07:58:15Z")

</div>

They're all seperated into fields by grok. I just want to get rid of the commas that appear with some of the field's values.

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [August 11, 2017, 12:19pm UTC](https://discuss.elastic.co/t/using-gsub-to-replace-field-values/96613/8 "2017-08-11T12:19:46Z")

</div>

`gsub => [“fwdPtPrecision”, “,”,""]`

Try this. It will replace all the commas in the field **fwdPtPrecision** with a blank string, effectively removing the commas from the field.

---

<div class="post-metadata">

**Author:** ![sentinel](https://avatars.discourse-cdn.com/v4/letter/s/fbc32d/32.png) [@sentinel](https://discuss.elastic.co/u/sentinel)\
**Post date:** [August 16, 2017, 9:33am UTC](https://discuss.elastic.co/t/using-gsub-to-replace-field-values/96613/9 "2017-08-16T09:33:15Z")

</div>

Thanks. That did the trick for all the bits I didn't want in there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2017, 9:33am UTC](https://discuss.elastic.co/t/using-gsub-to-replace-field-values/96613/10 "2017-09-13T09:33:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
