# Pipeline Rule with quotation mark

**URL:** <https://community.graylog.org/t/pipeline-rule-with-quotation-mark/28075>\
**Category:** Graylog Central (peer support)\
**Created:** [March 13, 2023, 3:01pm UTC](https://community.graylog.org/t/pipeline-rule-with-quotation-mark/28075 "2023-03-13T15:01:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DietmarSchurr](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dietmarschurr/32/10013_2.png) [@DietmarSchurr](https://community.graylog.org/u/DietmarSchurr)\
**Post date:** [March 13, 2023, 3:01pm UTC](https://community.graylog.org/t/pipeline-rule-with-quotation-mark/28075/1 "2023-03-13T15:01:05Z")

</div>

Hello,

in a GELF message which reads like this:  
`C63C28C45C67FE7-0000000000000017 QuittungsID: DWFENTW-f40c7bc2-b0bb-zzzf-ba6b-399591671e09, DruckauftragID: ZHP-ENTW-729abcb1-6ea0-4b00-fffz-828eb1b1bf8c-1, Message received from Rest-Consumer : {"HEADER":{"ERSTELLUNGS_ZEITPUNKT":"2023-03-10T10:38:31.000036+01:00","SCHNITTSTELLE":"DokumentQuittung","VERSION":1,"HERKUNFT":"DWF","AKTION":"","ORDNUNGSBEGRIFF_TYP":"QuittungsId","ORDNUNGSBEGRIFF":"DWFENTW-f40c7bc2-b0bb-48a8-ba6b-399591671e09","AUSLOESENDER_USER":"effe","AUSLOESENDE_ANWENDUNG":"Documendomm Workflow","UMGEBUNG":"ENTW"},"QUITTUNG":{"STATUS":"OK","STATUS_CODE":4001,"MESSAGE":"Dokument archiviert","ORDNUNGSBEGRIFF_TYP":"DruckauftragID","ORDNUNGSBEGRIFF":"ZHR-ENTW-729abcb1-6ea0-4b00-88a1-828eb1b1bf8c-1","ARCDOCID":"df4ba21da4f45673f9e8c711","CONTENT_REPOSITORY":"CB","AUFTRAG_HERKUNFT":"ZRP"}}`

the field StatusCode (4001) should be extracted with a regex expression:

> ```
> let m4 = regex(".*\"STATUS_CODE\":([4][0-9]{3}).*", to_string($message.message), ["statusCode"]);
> set_fields(m4); 
> 
> ```

But this does not work. How does this regex needs to look like?

Thanks in advance.

Dietmar Schurr

OS Information: openSuse 12.4  
Graylog Version: 4.3.12

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [March 13, 2023, 4:10pm UTC](https://community.graylog.org/t/pipeline-rule-with-quotation-mark/28075/2 "2023-03-13T16:10:51Z")

</div>

your `:` needs to be double escaped

Characters that need to be escaped:

```auto
& | : \ / + - ! ( ) { } [] ^ " ~ * ?

```

Also you may want

```auto
 set_fields(m4["0"]); 

```

---

<div class="post-metadata">

**Author:** ![DietmarSchurr](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dietmarschurr/32/10013_2.png) [@DietmarSchurr](https://community.graylog.org/u/DietmarSchurr)\
**Post date:** [March 14, 2023, 6:00am UTC](https://community.graylog.org/t/pipeline-rule-with-quotation-mark/28075/3 "2023-03-14T06:00:02Z")

</div>

Thank you very much.

Suddenly, if we use **full\_message** instead of **message** it works!

Regards,

Dietmar

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [March 28, 2023, 6:00am UTC](https://community.graylog.org/t/pipeline-rule-with-quotation-mark/28075/4 "2023-03-28T06:00:36Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
