# Filtering in Logstash for XML data

**URL:** <https://discuss.elastic.co/t/filtering-in-logstash-for-xml-data/147434>\
**Category:** Logstash\
**Created:** [September 5, 2018, 3:41pm UTC](https://discuss.elastic.co/t/filtering-in-logstash-for-xml-data/147434 "2018-09-05T15:41:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bharath\_Pusuluri](https://avatars.discourse-cdn.com/v4/letter/b/b9bd4f/32.png) [@Bharath\_Pusuluri](https://discuss.elastic.co/u/Bharath_Pusuluri)\
**Post date:** [September 5, 2018, 3:41pm UTC](https://discuss.elastic.co/t/filtering-in-logstash-for-xml-data/147434/1 "2018-09-05T15:41:04Z")

</div>

Need help in writing the right conf file for the data displayed here. Getting the splittable errors

Input file --- from the url

\<clusterMetrics\>

\<appsSubmitted\>12434\</appsSubmitted\>

\<appsCompleted\>12279\</appsCompleted\>

\<appsPending\>0\</appsPending\>

\<appsRunning\>9\</appsRunning\>

\<appsFailed\>13\</appsFailed\>

\<appsKilled\>133\</appsKilled\>

\<reservedMB\>0\</reservedMB\>

\<availableMB\>1050624\</availableMB\>

\<allocatedMB\>147456\</allocatedMB\>

\<reservedVirtualCores\>0\</reservedVirtualCores\>

\<availableVirtualCores\>60\</availableVirtualCores\>

\<allocatedVirtualCores\>24\</allocatedVirtualCores\>

\<containersAllocated\>24\</containersAllocated\>

\<containersReserved\>0\</containersReserved\>

\<containersPending\>0\</containersPending\>

\<totalMB\>1198080\</totalMB\>

\<totalVirtualCores\>84\</totalVirtualCores\>

\<totalNodes\>3\</totalNodes\>

\<lostNodes\>0\</lostNodes\>

\<unhealthyNodes\>0\</unhealthyNodes\>

\<decommissionedNodes\>0\</decommissionedNodes\>

\<rebootedNodes\>0\</rebootedNodes\>

\<activeNodes\>3\</activeNodes\>

\</clusterMetrics\>

Code:

Input used

exec {

```
type =&gt; "metrics"

command =&gt; "curl -s http://13.11.xxx.234:8088/ws/v1/cluster/metrics"

interval =&gt; "5"

codec =&gt; "json"

```

}

filter used

if [type] == "metrics"

{

```
 split {

         field =&gt; "metrics[clusterMetrics]"

         remove_field =&gt; ["command"]

 }

```

}

Output used

elasticsearch {

```
index =&gt; "yarn-metrics-%{+YYYY.MM.dd}"

document_type =&gt; "doc"

codec =&gt; "json"

```

servername...

username

password..  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 5, 2018, 4:59pm UTC](https://discuss.elastic.co/t/filtering-in-logstash-for-xml-data/147434/2 "2018-09-05T16:59:50Z")

</div>

- Why run curl instead of using the http\_poller input plugin?
- If curl indeed returns XML you should remove `codec => json`.
- To parse the XML use an xml filter.
- The point of the split filter is unclear. That filter requires an array as input and transforming the XML in your example won't produce any arrays.

---

<div class="post-metadata">

**Author:** ![Bharath\_Pusuluri](https://avatars.discourse-cdn.com/v4/letter/b/b9bd4f/32.png) [@Bharath\_Pusuluri](https://discuss.elastic.co/u/Bharath_Pusuluri)\
**Post date:** [September 6, 2018, 12:37am UTC](https://discuss.elastic.co/t/filtering-in-logstash-for-xml-data/147434/3 "2018-09-06T00:37:12Z")

</div>

Hi Magnus,

Based on your suggestions I changed to http polar and also used the xml.

The code with Jason and also Xml, http polar all are working in 5.6 version of elastic but failing with 5.2.1 version.

It is throwing splittable errors

Regards,  
Bharath

---

<div class="post-metadata">

**Author:** ![Bharath\_Pusuluri](https://avatars.discourse-cdn.com/v4/letter/b/b9bd4f/32.png) [@Bharath\_Pusuluri](https://discuss.elastic.co/u/Bharath_Pusuluri)\
**Post date:** [September 6, 2018, 12:39am UTC](https://discuss.elastic.co/t/filtering-in-logstash-for-xml-data/147434/4 "2018-09-06T00:39:38Z")

</div>

How to check the split filter value , can u suggest? I am writing the logstash conf for the first time

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 6, 2018, 6:15am UTC](https://discuss.elastic.co/t/filtering-in-logstash-for-xml-data/147434/5 "2018-09-06T06:15:59Z")

</div>

Instead of describing what you see, show us. What does an example event look like? Use a `stdout { codec => rubydebug }` output to dump the raw event.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2018, 6:16am UTC](https://discuss.elastic.co/t/filtering-in-logstash-for-xml-data/147434/6 "2018-10-04T06:16:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
