# Filebeat to analyze xml logs

**URL:** <https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305>\
**Category:** Logs\
**Created:** [September 5, 2023, 5:58am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305 "2023-09-05T05:58:00Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ted0011](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Post date:** [September 5, 2023, 5:58am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305/1 "2023-09-05T05:58:00Z")

</div>

Hello Its Suman Ghorashine

I am new to wazuh and ELK stack. And I wanted to know some certain things.

I have a xml log format set to wazuh server for analysis from agent configuration file. But when filtering the logs from location filter in Wazuh I am getting nothing it says empty and try different time format which I did with no luck.

Any help on this matter would be greatly appreciated.

We are using Filebeat, Elasticsearch, and Kibana stack.

---

<div class="post-metadata">

**Author:** ![miltonhultgren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miltonhultgren/32/100401_2.png) [@miltonhultgren](https://discuss.elastic.co/u/miltonhultgren)\
**Post date:** [September 5, 2023, 7:26am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305/2 "2023-09-05T07:26:22Z")

</div>

Hi!  
I'm not sure I understand the set up you're using. If you're having issues within Wazuh (the standalone app or the Kibana plugin) you should direct your question to the developers of that software.

If you're having issues within Kibana or with your data management in Elasticsearch for the data collected with Filebeat then please explain what issue you're facing within the Elastic stack!

Are you able to view your logs using Discover for example?

---

<div class="post-metadata">

**Author:** ![Ted0011](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Post date:** [September 5, 2023, 8:38am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305/3 "2023-09-05T08:38:36Z")

</div>

Thank for you response.

I have configured my wazuh agent from /var/ossec/etc/ossec.conf like

```auto
  <localfile>
    <log_format>syslog</log_format>
    <location>/var/log/izt/QRIF/qrif.log</location>
  </localfile>

```

The qrif.log is in xml format and I want to view this log on my wazuh dashboard.

**These logs are processed by Wazuh Manager which is run on top of analytics engine Elasticsearch and visualizes those data in Kibana.**

I am not getting any logs on Discover.

---

<div class="post-metadata">

**Author:** ![miltonhultgren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miltonhultgren/32/100401_2.png) [@miltonhultgren](https://discuss.elastic.co/u/miltonhultgren)\
**Post date:** [September 5, 2023, 9:33am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305/4 "2023-09-05T09:33:35Z")

</div>

I see.

Can you share your Filebeat config as well for how you collect the logs from `qrif.log`?  
Do you have any errors in your console log from Filebeat?  
In Kibana, withing Stack Management -\> Index management, can you see any `filebeat-*` indices?

Let's first establish that you're actually getting logs into Elasticsearch and go from there!

---

<div class="post-metadata">

**Author:** ![Ted0011](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Post date:** [September 5, 2023, 10:09am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305/5 "2023-09-05T10:09:59Z")

</div>

Here is my filebeat.yml file..

```auto
# Wazuh - Filebeat configuration file
filebeat.modules:
  - module: wazuh
    alerts:
      enabled: true
    archives:
      enabled: false

setup.template.json.enabled: true
setup.template.json.path: '/etc/filebeat/wazuh-template.json'
setup.template.json.name: 'wazuh'
setup.template.overwrite: true
setup.ilm.enabled: false

output.elasticsearch.hosts: ['127.0.0.1:9200']
output.elasticsearch.protocol: https
output.elasticsearch.ssl.certificate: "/etc/filebeat/certs/wazuh-manager.crt"
output.elasticsearch.ssl.key: "/etc/filebeat/certs/wazuh-manager.key"
output.elasticsearch.ssl.certificate_authorities: ["/etc/filebeat/certs/ca/ca.crt"]

output.elasticsearch.username: "<user>"
output.elasticsearch.password: "<password>"

filebeat.config.modules:
  enabled: true
  path: ${path.config}/modules.d/*.yml

```

Where should I paste the location of the log to be monitored for my scenario. I only have added the log location on /var/ossec/etc/ossec.conf on agent side.

We are not getting our logs of qrif.log anywhere. Can you please tell me where will the logs be sent based on following configuration on ossec.conf from /var/ossec/etc/ossec.conf on agent side.

```auto
 <localfile>
    <log_format>syslog</log_format>
    <location>/var/log/izt/QRIF/qrif.log</location>
  </localfile>

```

Not any issue I see on filebeat log.

Also, we have filebeat-\* Stack Management -\> Index management

On our documentation I found that our wazuh agent sends all the logs sent to the wazuh manger and from that we send the logs to elasticsearch and kibana.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 5, 2023, 11:27am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305/6 "2023-09-05T11:27:35Z")

</div>

> [@Ted0011](#):
>
> We are not getting our logs of qrif.log anywhere. Can you please tell me where will the logs be sent based on following configuration on ossec.conf from /var/ossec/etc/ossec.conf on agent side.

Your issue seems to be with your Wazuh configuration, Wazuh is not supported here, you will need to contact the Wazuh developers on their github.

If your `qrif.log` is a multi-line xml file, you cannot use `syslog` as the `log_format` in your `ossec.conf`.

Wazuh can read multi-line files, but I'm not sure how you will need to configure it, you need to check the Wazuh documentation and ask the Wazuh developers.

---

<div class="post-metadata">

**Author:** ![Ted0011](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Post date:** [September 5, 2023, 11:46am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305/7 "2023-09-05T11:46:38Z")

</div>

Yes qrif.log in xml is a multi-line file.

Does that mean I have to change my wazuh manager configuration to check the multi-line files.

But I am not getting any kind of logs in even wazuh manager of any sort including qrif.log if I try to filter from location: /var/log/izt/QRIF/qrif.log on KQL filter.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 5, 2023, 12:06pm UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305/8 "2023-09-05T12:06:37Z")

</div>

> [@Ted0011](#):
>
> But I am not getting any kind of logs in even wazuh manager

As mentioned earlier, Wazuh is not supported here, you need to contact the Wazuh developers if you are having any issues with Wazuh.

If you can see other logs from Wazuh in your Elasticsearch, then there is no issue in Filebeat, it will just read the Wazuh logs.

If the log you want is not present in the Wazuh logs, then your issue is with Wazuh and you need to contact the community/developers to understand how to solve it.

---

<div class="post-metadata">

**Author:** ![Ted0011](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Post date:** [September 6, 2023, 3:53am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305/9 "2023-09-06T03:53:56Z")

</div>

Thank you so much for your help.

I will get back to you about the update I do.

Again Thank you so much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2023, 3:54am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305/10 "2023-10-04T03:54:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
