# \#regex-special-charac

**URL:** https://community.graylog.org/tag/regex-special-charac/10.md

[Latest](https://community.graylog.org/latest.md) · [Categories](https://community.graylog.org/categories.md) · [Tags](https://community.graylog.org/tags.md)

---

## [Using a dot in a regex replacement string](https://community.graylog.org/t/using-a-dot-in-a-regex-replacement-string/36374)

<div class="topic-metadata">

**Author:** [@d\_a\_parker](https://community.graylog.org/u/d_a_parker)\
**Replies:** 1\
**Last updated:** [October 1, 2025, 2:19pm UTC](https://community.graylog.org/t/using-a-dot-in-a-regex-replacement-string/36374 "2025-10-01T14:19:36Z")

</div>

Hi All, Running Graylog 5.0.3 and I’m having an issue using a Replace with Regular Expression extractor with a literal dot in the replacement string. We get access log message from NGINX via a filebeat sidecar, so they …

---

## [Errors/issues in pipeline rule builder: Invalid expression, not adding new field](https://community.graylog.org/t/errors-issues-in-pipeline-rule-builder-invalid-expression-not-adding-new-field/34237)

<div class="topic-metadata">

**Author:** [@marziglt](https://community.graylog.org/u/marziglt)\
**Replies:** 1\
**Last updated:** [November 20, 2024, 5:30pm UTC](https://community.graylog.org/t/errors-issues-in-pipeline-rule-builder-invalid-expression-not-adding-new-field/34237 "2024-11-20T17:30:36Z")

</div>

Using Graylog Open 6.1, we’re trying to parse the Category from an incoming log stream derived from the OpenSearch cluster log file. Sample message: servername file-osgraylog: \[2024-11-19T13:22:07,732\]\[INFO \]\[o.o.j.s.…

---

## [Fighting the square brackets, need help with regex](https://community.graylog.org/t/fighting-the-square-brackets-need-help-with-regex/33401)

<div class="topic-metadata">

**Author:** [@invert123](https://community.graylog.org/u/invert123)\
**Replies:** 1\
**Last updated:** [September 3, 2024, 10:16am UTC](https://community.graylog.org/t/fighting-the-square-brackets-need-help-with-regex/33401 "2024-09-03T10:16:07Z")

</div>

Hi All, I need to create a pipeline rule to extract the name of the component from my Mule-based application. This name I then store in a separate field. Done this many times using simple regex, but the square brackets…

---

## [Issues with Cisco Grok pattern](https://community.graylog.org/t/issues-with-cisco-grok-pattern/33243)

<div class="topic-metadata">

**Author:** [@ffeingol](https://community.graylog.org/u/ffeingol)\
**Replies:** 5\
**Last updated:** [August 16, 2024, 8:15am UTC](https://community.graylog.org/t/issues-with-cisco-grok-pattern/33243 "2024-08-16T08:15:53Z")

</div>

I’m using the following Grok pattern to extra data from a Cisco device: %{GREEDYDATA:UNWANTED} %%{GREEDYDATA:cisco\_first}?-%{GREEDYDATA:cisco\_status}?-%{GREEDYDATA:cisco\_last}?: %{GREEDYDATA:cisco\_message} Example log …

---

## [Masking Sensitive Data on Graylog Pipeline Rules Script](https://community.graylog.org/t/masking-sensitive-data-on-graylog-pipeline-rules-script/33015)

<div class="topic-metadata">

**Author:** [@kctan](https://community.graylog.org/u/kctan)\
**Replies:** 1\
**Last updated:** [July 18, 2024, 3:45am UTC](https://community.graylog.org/t/masking-sensitive-data-on-graylog-pipeline-rules-script/33015 "2024-07-18T03:45:20Z")

</div>

Hello there Graylog Community, I want to mask the username but it does not work and only return the original message response. I have this Rule source: rule "mask\_sensitive\_fields" when has\_field("message") then le…

---

## [Search domain to match any occurrence on string](https://community.graylog.org/t/search-domain-to-match-any-occurrence-on-string/32403)

<div class="topic-metadata">

**Author:** [@Gabao-Farias](https://community.graylog.org/u/Gabao-Farias)\
**Replies:** 0\
**Last updated:** [May 14, 2024, 1:59pm UTC](https://community.graylog.org/t/search-domain-to-match-any-occurrence-on-string/32403 "2024-05-14T13:59:21Z")

</div>

Hi guys! I still could not understand why while searching in the graylog a specific domain, it cannot match the subdomain address containing the domain searched… Am I searching it wrong or this way of searching would s…

---

## [Search issue with double colons](https://community.graylog.org/t/search-issue-with-double-colons/32159)

<div class="topic-metadata">

**Author:** [@intpdm](https://community.graylog.org/u/intpdm)\
**Replies:** 3\
**Last updated:** [April 19, 2024, 12:13pm UTC](https://community.graylog.org/t/search-issue-with-double-colons/32159 "2024-04-19T12:13:32Z")

</div>

Hi. Are there any restrictions on searching in graylog? Because i tried to find message with text having double colons ( :: ) and not get any results, but if i look by timestamp i can see it. There is no errors in gra…

---

## [regex to filter files without extension](https://community.graylog.org/t/regex-to-filter-files-without-extension/31695)

<div class="topic-metadata">

**Author:** [@damielbr](https://community.graylog.org/u/damielbr)\
**Replies:** 2\
**Last updated:** [March 5, 2024, 10:42pm UTC](https://community.graylog.org/t/regex-to-filter-files-without-extension/31695 "2024-03-05T22:42:28Z")

</div>

Hi guys, i’m new here, i’m using version 5.0. i’ve tried chatGPT and google but i can’t find a way to filter files without extensions using regex…i don’t want them to appear in the results. it’s possible? thanks!!

---

## [Issue with parsing regex expression in pipelines](https://community.graylog.org/t/issue-with-parsing-regex-expression-in-pipelines/31108)

<div class="topic-metadata">

**Author:** [@ejensen](https://community.graylog.org/u/ejensen)\
**Replies:** 7\
**Last updated:** [January 3, 2024, 4:15pm UTC](https://community.graylog.org/t/issue-with-parsing-regex-expression-in-pipelines/31108 "2024-01-03T16:15:33Z")

</div>

Hello, I am using Graylog version 5.2.2, and I am encountering an issue with parsing JSON from a message string within pipeline rules. The log messages have the following format: cnmaestro cnmaestro\[4076\]: {Json} I’ve…

---

## [How to test field value using regex? in favor to determ if extractor has to run](https://community.graylog.org/t/how-to-test-field-value-using-regex-in-favor-to-determ-if-extractor-has-to-run/30738)

<div class="topic-metadata">

**Author:** [@louis](https://community.graylog.org/u/louis)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 1:41pm UTC](https://community.graylog.org/t/how-to-test-field-value-using-regex-in-favor-to-determ-if-extractor-has-to-run/30738 "2023-11-20T13:41:00Z")

</div>

I am building extractors to parse an alarmlog with comma separated fields. Depending on field values I need to use a a different extractor. So I use the only execute extractor if regex is true field. However that is ea…

---

## [How to set date while creating index rotating strategy in time](https://community.graylog.org/t/how-to-set-date-while-creating-index-rotating-strategy-in-time/30199)

<div class="topic-metadata">

**Author:** [@Bee8080](https://community.graylog.org/u/Bee8080)\
**Replies:** 2\
**Last updated:** [October 6, 2023, 10:40am UTC](https://community.graylog.org/t/how-to-set-date-while-creating-index-rotating-strategy-in-time/30199 "2023-10-06T10:40:26Z")

</div>

Hello Community, I wanted to set index prefix with something like graylog\_alert\_MM\_DD\_YYYY for everyday since it rotates but until now i have only achieved graylog\_alert\_0, next day graylog\_alert\_1. I want to do someth…

---

## [Drop one specific logline in filebeat (multiline in use)](https://community.graylog.org/t/drop-one-specific-logline-in-filebeat-multiline-in-use/30135)

<div class="topic-metadata">

**Author:** [@bavarian](https://community.graylog.org/u/bavarian)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 3:22am UTC](https://community.graylog.org/t/drop-one-specific-logline-in-filebeat-multiline-in-use/30135 "2023-09-20T03:22:26Z")

</div>

I am using with sidecar filebeat configuration multiline patterns, which works fine, kinda. But I have one line which gets wraps up, which I do not want to have in that message and should be dropped. My current filebea…

---

## [Escape string values from json input in pipeline](https://community.graylog.org/t/escape-string-values-from-json-input-in-pipeline/30038)

<div class="topic-metadata">

**Author:** [@gothmodule](https://community.graylog.org/u/gothmodule)\
**Replies:** 6\
**Last updated:** [September 8, 2023, 5:34am UTC](https://community.graylog.org/t/escape-string-values-from-json-input-in-pipeline/30038 "2023-09-08T05:34:39Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [Graylog Extractor by Regular Expression](https://community.graylog.org/t/graylog-extractor-by-regular-expression/29955)

<div class="topic-metadata">

**Author:** [@davidfungf](https://community.graylog.org/u/davidfungf)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 2:12pm UTC](https://community.graylog.org/t/graylog-extractor-by-regular-expression/29955 "2023-09-05T14:12:16Z")

</div>

How do I extract the json data {…} and eliminate the “created live/iot” by Graylog regular expression? Thanks. created live/iot {"consumerGroup":"iot-gtwinsg","eventBody":{"iotData":\[{"id":{"reading":"293790536467218432…

---

## [Pipelines and regex (and some extractor talk)](https://community.graylog.org/t/pipelines-and-regex-and-some-extractor-talk/29338)

<div class="topic-metadata">

**Author:** [@kawaiipantsu](https://community.graylog.org/u/kawaiipantsu)\
**Replies:** 5\
**Last updated:** [June 27, 2023, 9:05pm UTC](https://community.graylog.org/t/pipelines-and-regex-and-some-extractor-talk/29338 "2023-06-27T21:05:19Z")

</div>

The TL;DR is that i’m trying to make a pipeline with a rule that parses my bind9/named query log messages. New to graylog pipelines but not new to regex :slight\_smile: But a trued and tried regex that works in regex te…

---

## [Regex\_replace certain chacacter within quotes](https://community.graylog.org/t/regex-replace-certain-chacacter-within-quotes/27858)

<div class="topic-metadata">

**Author:** [@Phoebus](https://community.graylog.org/u/Phoebus)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 2:28pm UTC](https://community.graylog.org/t/regex-replace-certain-chacacter-within-quotes/27858 "2023-02-27T14:28:43Z")

</div>

Hi all, I’m trying to remove equals signs from within quotes inside message. Example qives you an idea what’s the problem: field1=value field2="value=with=equals" field3="something else" key=value extractor does a havo…

---

## [Regex's extractor doesn't going well](https://community.graylog.org/t/regexs-extractor-doesnt-going-well/27619)

<div class="topic-metadata">

**Author:** [@nov4n-4r](https://community.graylog.org/u/nov4n-4r)\
**Replies:** 4\
**Last updated:** [February 7, 2023, 10:59pm UTC](https://community.graylog.org/t/regexs-extractor-doesnt-going-well/27619 "2023-02-07T22:59:51Z")

</div>

Hey there I need ur help plssss :)), I’ve tried to make an extractor to extract my fortigate’s logs using regex. I want to grep value of crlevel field with any criteria, but in the preview it’s just crlevel with “high” v…

---

## [Filebeat: Using multiline to split Microsoft Defender for Endpoint events into separate messages in Graylog](https://community.graylog.org/t/filebeat-using-multiline-to-split-microsoft-defender-for-endpoint-events-into-separate-messages-in-graylog/27523)

<div class="topic-metadata">

**Author:** [@SalC](https://community.graylog.org/u/SalC)\
**Replies:** 5\
**Last updated:** [February 2, 2023, 3:57pm UTC](https://community.graylog.org/t/filebeat-using-multiline-to-split-microsoft-defender-for-endpoint-events-into-separate-messages-in-graylog/27523 "2023-02-02T15:57:47Z")

</div>

I’m grabbing Microsoft Defender for Endpoint events using a powershell script, which outputs all the events for a given duration to a single file. I’m then reading the file into Graylog using filebeat on Windows. The e…

---

## [Unifi syslog, stream, pipline, regex](https://community.graylog.org/t/unifi-syslog-stream-pipline-regex/27047)

<div class="topic-metadata">

**Author:** [@schneich](https://community.graylog.org/u/schneich)\
**Replies:** 10\
**Last updated:** [December 28, 2022, 9:34pm UTC](https://community.graylog.org/t/unifi-syslog-stream-pipline-regex/27047 "2022-12-28T21:34:11Z")

</div>

Dear community, I am working on my first pipeline rule. I stumbled accross something, I don’t understand. I want to parse a message and use regex to write values in additional fields. I am pretty sure, that my regex is …

---

## [\[Graylog Coommunity 4.2.5\] Need help with a regex pipeline](https://community.graylog.org/t/graylog-coommunity-4-2-5-need-help-with-a-regex-pipeline/22406)

<div class="topic-metadata">

**Author:** [@hmb104](https://community.graylog.org/u/hmb104)\
**Replies:** 12\
**Last updated:** [January 21, 2022, 10:16pm UTC](https://community.graylog.org/t/graylog-coommunity-4-2-5-need-help-with-a-regex-pipeline/22406 "2022-01-21T22:16:49Z")

</div>

1. Describe your incident: I have the following log messages from HPE network switches. \*\<190\>Jan 19 17:07:22 2022 pr1net161 %%10SSHS/6/SSHS\_LOG: User networkad logged out from 10.4.28.27 port 41078\* As you can see, i…

---

## [Parsing nested json from JSON path HTTP API input](https://community.graylog.org/t/parsing-nested-json-from-json-path-http-api-input/22323)

<div class="topic-metadata">

**Author:** [@jimbo](https://community.graylog.org/u/jimbo)\
**Replies:** 2\
**Last updated:** [January 14, 2022, 11:33am UTC](https://community.graylog.org/t/parsing-nested-json-from-json-path-http-api-input/22323 "2022-01-14T11:33:31Z")

</div>

Hi dear enthusiasts, I am using dockerised graylog 4.2 using docker-compose. I input json data from an api using JSON path HTTP API input. This is what the json data looks like from the api: { "processGroupStatus": …

---

## [Use Contains in a pipeline rule with double quote](https://community.graylog.org/t/use-contains-in-a-pipeline-rule-with-double-quote/21454)

<div class="topic-metadata">

**Author:** [@Pourya](https://community.graylog.org/u/Pourya)\
**Replies:** 4\
**Last updated:** [October 14, 2021, 6:49am UTC](https://community.graylog.org/t/use-contains-in-a-pipeline-rule-with-double-quote/21454 "2021-10-14T06:49:27Z")

</div>

Hello I’ve tried to read up the docs and this forum before posting this but couldn’t find similar issue. I’m trying to implement a pipeline rule like below to route certain message based on a string. rule "New\_Route" …

---

## [Pipelines with regex and special character](https://community.graylog.org/t/pipelines-with-regex-and-special-character/641)

<div class="topic-metadata">

**Author:** [@ryz.namathp](https://community.graylog.org/u/ryz.namathp)\
**Replies:** 6\
**Last updated:** [April 11, 2018, 3:34pm UTC](https://community.graylog.org/t/pipelines-with-regex-and-special-character/641 "2018-04-11T15:34:20Z")

</div>

Hi All, I am facing issue with pipeline and regex, in my regex i have special character \[, to escape this I am using \\\\\[, you can see the complete regex below, while doing pipeline simulator getting extra \\ in results…
