# Extract Info from Field using Logstash

**URL:** <https://discuss.elastic.co/t/extract-info-from-field-using-logstash/248883>\
**Category:** Logstash\
**Created:** [September 16, 2020, 9:00pm UTC](https://discuss.elastic.co/t/extract-info-from-field-using-logstash/248883 "2020-09-16T21:00:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rsuper\_6616](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsuper_6616/32/48333_2.png) [@rsuper\_6616](https://discuss.elastic.co/u/rsuper_6616)\
**Post date:** [September 16, 2020, 9:00pm UTC](https://discuss.elastic.co/t/extract-info-from-field-using-logstash/248883/1 "2020-09-16T21:00:48Z")

</div>

Hi  
I have a field in ELK and I am using logstash v7 to extract the logs from Elastic to CSV and I have a field that part of it contains XML and Json how can I write a filter plugin that can get the XML Part or (JSON) it usually starts with **Body:**

```
 Method:POST
 query string:
 Browser: Unknown
 Headers:
 Cache-Control=no-cache
 Connection=Keep-Alive
 Pragma=no-cache
 Content-Length=667
 Content-Type=text/xml; charset=utf-8
 Accept=application/soap+xml, application/dime, multipart/related, text/
 Host=live.xxxxx.me
 User-Agent=Axis/1.4
 X_FORWARDED_FOR=xx.xx.xx.xx
SOAPAction=""
MS-ASPNETCORE-TOKEN=xxxxxxxxxxxxxxxxx
X-Original-Proto=http
X-Original-For=127.0.0.1:xxxxx
singularityheader=notxdetect=True
 ============================================================================
Body:
<?xml version="1.0" encoding="UTF-8"?><soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"><soapenv:Body><notifySmsReception xmlns="http://www.csapi.org/schema/parlayx/sms/notification/v2_1/local"><correlator>tel99808885</correlator><message><message xmlns="">XXXXXX;XXXXXXXXX;XXXXXX;;D;SM_fce63667-4b04-48b5-8fa1-c26ed0277820;;T;1010</message><senderAddress xmlns="">tel:XXXXXXXXXXXX</senderAddress><smsServiceActivationNumber xmlns="">tel:XXXXXXXXXX</smsServiceActivationNumber></message></notifySmsReception></soapenv:Body></soapenv:Envelope>
========================================================================
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 16, 2020, 9:17pm UTC](https://discuss.elastic.co/t/extract-info-from-field-using-logstash/248883/2 "2020-09-16T21:17:19Z")

</div>

If that is your [message] field then just pass it to an XML filter.

```
xml { store_xml => true source => "message" target => "someField" }

```

The filter will figure out where the XML starts and ends (provided you do not use xpath -- that requires the source to be valid XML).

---

<div class="post-metadata">

**Author:** ![rsuper\_6616](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsuper_6616/32/48333_2.png) [@rsuper\_6616](https://discuss.elastic.co/u/rsuper_6616)\
**Post date:** [September 16, 2020, 11:25pm UTC](https://discuss.elastic.co/t/extract-info-from-field-using-logstash/248883/3 "2020-09-16T23:25:40Z")

</div>

> [@Badger](#):
>
> `xml { store_xml => true source => "message" target => "someField" }`

thanks Badger it works but I can't extract any field from the result field as it is not valid xml or json

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2020, 11:25pm UTC](https://discuss.elastic.co/t/extract-info-from-field-using-logstash/248883/4 "2020-10-14T23:25:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
