Filtering in Logstash for XML data

Need help in writing the right conf file for the data displayed here. Getting the splittable errors

Input file --- from the url



























Input used

exec {

type =&gt; "metrics"

command =&gt; "curl -s"

interval =&gt; "5"

codec =&gt; "json"


filter used

if [type] == "metrics"


 split {

         field =&gt; "metrics[clusterMetrics]"

         remove_field =&gt; [ "command" ]



Output used

elasticsearch {

index =&gt; "yarn-metrics-%{+YYYY.MM.dd}"

document_type =&gt; "doc"

codec =&gt; "json"




  • Why run curl instead of using the http_poller input plugin?
  • If curl indeed returns XML you should remove codec => json.
  • To parse the XML use an xml filter.
  • The point of the split filter is unclear. That filter requires an array as input and transforming the XML in your example won't produce any arrays.

Hi Magnus,

Based on your suggestions I changed to http polar and also used the xml.

The code with Jason and also Xml, http polar all are working in 5.6 version of elastic but failing with 5.2.1 version.

It is throwing splittable errors


How to check the split filter value , can u suggest? I am writing the logstash conf for the first time

Instead of describing what you see, show us. What does an example event look like? Use a stdout { codec => rubydebug } output to dump the raw event.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.