# Append metadata to every event in XML file being ingested to Elasticsearch

**URL:** <https://discuss.elastic.co/t/append-metadata-to-every-event-in-xml-file-being-ingested-to-elasticsearch/165914>\
**Category:** Logstash\
**Created:** [January 27, 2019, 7:23pm UTC](https://discuss.elastic.co/t/append-metadata-to-every-event-in-xml-file-being-ingested-to-elasticsearch/165914 "2019-01-27T19:23:25Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 27, 2019, 9:20pm UTC](https://discuss.elastic.co/t/append-metadata-to-every-event-in-xml-file-being-ingested-to-elasticsearch/165914/2 "2019-01-27T21:20:35Z")

</div>

I assume your xml file will have \</events\> and \</eventdata\>. If not it is not valid XML, but that can be fixed with a mutate+ gsub to append text to the message if needed.

Consume the entire XML as a single event using a file input and a multiline codec that never matches. For example

```
codec => multiline { pattern => "^Spalanzani" negate => true what => "previous" auto_flush_interval => 1 } 

```

Then you can parse the XML and split on the event field

```
xml { source => "message" target => "theXML" store_xml => true }
split { field => "[theXML][events][0][event]" }

```

Then you just have [mutate+rename](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-rename) all the fields to get them where you want them.

---

_[View the full topic](https://discuss.elastic.co/t/append-metadata-to-every-event-in-xml-file-being-ingested-to-elasticsearch/165914)._
