# Create an array from a nested XML field

**URL:** <https://discuss.elastic.co/t/create-an-array-from-a-nested-xml-field/37377>\
**Category:** Logstash\
**Created:** [December 16, 2015, 4:18pm UTC](https://discuss.elastic.co/t/create-an-array-from-a-nested-xml-field/37377 "2015-12-16T16:18:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shayleen](https://avatars.discourse-cdn.com/v4/letter/s/cc9497/32.png) [@Shayleen](https://discuss.elastic.co/u/Shayleen)\
**Post date:** [December 16, 2015, 4:18pm UTC](https://discuss.elastic.co/t/create-an-array-from-a-nested-xml-field/37377/1 "2015-12-16T16:18:19Z")

</div>

Hi,

I'm quite new in ELK and I've encountered a problem almost imposible to break for me.

I have an XML like this:  
\< root \>  
\< field\_A\>  
\< subfield\_A \>8100291240  
\< subfield\_B \>3  
\< subfield\_C \>6000436355  
\< subfield\_D \>  
\< subfield\_DD \>1000  
\</ subfield\_D \>  
\</ field\_A\>  
...  
\< field\_A\>  
\< subfield\_A \>8100291240  
\< subfield\_B \>3  
\< subfield\_C \>6000436355  
\< subfield\_D \>  
\< subfield\_DD \>1000  
\</ subfield\_D \>  
\</ field\_A\>

The field\_A with that format repets for the whole XML thousands of times. My first approach was to use the XML filter to obtain the elements, but I only need two subfields from field\_A.

At first, I used this:  
add\_field =\> {  
field\_A =\> "%{[root][field\_A][0][subfield\_A]}"  
}

I changed the 0 for a 1, and true enough, I was able to access the second element of the array. It worked like charm but... The problem is that I need to use the same field ALL the time and I don't know beforehand how many "field\_A" can I find in the XML. I tried to look for some kind of loop in logstash... No luck.

So, I decided to use the ruby filter, it took me a while but I was able to navigate inside the nested fields but again, same problem, I could only access to an specific element. For that I used this:

code =\> "event['root'] = event['root']['field\_A'][1]['subfield\_A']".

So, my question is, how can I use a single key for logstash, having multiple values knowing that this "funcionality" is written inside a way larger configuration file?

In other words, ideally, I'll need something like this:

field\_A =\> {  
[subfield\_A , subfield\_B],  
[subfield\_A , subfield\_B],  
.  
.  
.  
[subfield\_A , subfield\_B]  
}

I'm already losing my mind, any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [December 16, 2015, 4:23pm UTC](https://discuss.elastic.co/t/create-an-array-from-a-nested-xml-field/37377/2 "2015-12-16T16:23:32Z")

</div>

I'm going to change the category here to Logstash as you will get access to more people who know about Logstash that way.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 17, 2015, 10:55am UTC](https://discuss.elastic.co/t/create-an-array-from-a-nested-xml-field/37377/3 "2015-12-17T10:55:59Z")

</div>

So... you want to extract the contents of all subfield\_A and subfield\_B subelements from all field\_A elements?

Turn

```auto
<root>
  <fieldA>
    <subfield_A>1</subfield_A>
    <subfield_A>2</subfield_A>
  </fieldA>
  <fieldA>
    <subfield_A>3</subfield_A>
    <subfield_A>4</subfield_A>
  </fieldA>
</root>

```

into this:

```auto
{
  "field_A": ["1", "2", "3", "4"]
  ...
}

```

---

<div class="post-metadata">

**Author:** ![Shayleen](https://avatars.discourse-cdn.com/v4/letter/s/cc9497/32.png) [@Shayleen](https://discuss.elastic.co/u/Shayleen)\
**Post date:** [December 17, 2015, 11:18am UTC](https://discuss.elastic.co/t/create-an-array-from-a-nested-xml-field/37377/4 "2015-12-17T11:18:50Z")

</div>

Hello, Magnus

Thanks for your answer, but I already know how to extract a single occurrency of field\_A, my problem is, how to do that recursively AND store that information in the same field (with the same name).

All I've achieved so far is to overwritte the previous value or save only the first one.

Besides, I don't need only the value of the tags subfield\_A and subfield\_C, I also need to save the names of the tags to create a field in within, because I need to use those fields in my searchs on Kibana.

TURN THIS:  
\< root\>  
\< shirt\>  
\< color\>red\< /color\>  
\< size\>5\< /size\>  
\< /shirt\>  
.  
.  
.  
\< shirt\>  
\< color\>white\< /color\>  
\< size\>6\< /size\>  
\< /shirt\>  
\< /root\>

INTO THIS:  
{  
"shirt": [  
[[ [color],"red"] , [[size], 5] ],  
.  
.  
.  
[[ [color],"white"] , [[size], 6] ], ]  
}

Do you know how to do this? Thanks for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:18am UTC](https://discuss.elastic.co/t/create-an-array-from-a-nested-xml-field/37377/5 "2017-07-06T05:18:03Z")

</div>


