# Getting \_split\_type\_failure while splitting xml, not sure why but records are processed

**URL:** <https://discuss.elastic.co/t/getting-split-type-failure-while-splitting-xml-not-sure-why-but-records-are-processed/177608>\
**Category:** Logstash\
**Created:** [April 19, 2019, 10:52am UTC](https://discuss.elastic.co/t/getting-split-type-failure-while-splitting-xml-not-sure-why-but-records-are-processed/177608 "2019-04-19T10:52:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![saif3r](https://avatars.discourse-cdn.com/v4/letter/s/49beb7/32.png) [@saif3r](https://discuss.elastic.co/u/saif3r)\
**Post date:** [April 19, 2019, 10:52am UTC](https://discuss.elastic.co/t/getting-split-type-failure-while-splitting-xml-not-sure-why-but-records-are-processed/177608/1 "2019-04-19T10:52:36Z")

</div>

Hello All,

Based on an advice from earlier post, I created a config responsible for splitting my xml into multiple events. It looks like this:

```
input {
	file {
		path => "/mnt/abc/*.xml"
		start_position => "beginning"
	}
}

filter {
	if [message] =~ /<BATCH.*$/ {
		xml { 
			source => "message" 
			target => "theXML" 
			store_xml => true 
		}
		split { 
			field => "[theXML][PANEL][0][DUT]" 
		}
		split { 
			field => "[theXML][PANEL][0][DUT][GROUP][0]" 
		}
		split { 
			field => "[theXML][PANEL][0][DUT][GROUP][0][GROUP]" 
		}
		split { 
			field => "[theXML][PANEL][0][DUT][GROUP][0][GROUP][TEST]" 
		}
	} 
	else {
		drop { }
	}
}

output {
	stdout {
	}
	elasticsearch {
		hosts => ["10.10.10.10:9200]
		index => "abc"
		http_compression => true
	}
}

```

And here's part of my xml (added line breaks for better view, usually it's single line):

```
<?xml version="1.0" encoding="UTF-8"?>
<BATCH TIMESTAMP="2019-03-04T07:28:42.208+01:00">
  <FACTORY NAME="PARIS" />
  <PRODUCT NAME="PRODUCT"/>
  <REFS SEQ_REF=""/>
  <PANEL ID="1" COMMENT="">
    <DUT ID="1111" COMMENT="">
      <GROUP NAME="Main">
        <GROUP NAME="First_Test_Group">
          <TEST NAME="Test_1"/>
          <TEST NAME="Test_1"/>
          <TEST NAME="Test_1"/>
          <TEST NAME="Test_1"/>
        </GROUP>
        <GROUP NAME="Main_2"/>
      </GROUP>
    </DUT>
  </PANEL>
</BATCH>

```

Here's the stdout output:

[http://oneclickpaste.com/3401/](http://oneclickpaste.com/3401/)

One record view from Kibana:

 ![2019-04-19%2013_02_24-Discover%20-%20Kibana](https://us1.discourse-cdn.com/elastic/original/3X/1/7/17f1ae70e251f3ca1a3696599d9a6e509d84d299.png)

Logstash properly generated 5 events and put them into Elastic, but each event has a _ **\_split\_type\_failure** _ and I'm not sure what might be the outcome later on. What am I doing wrong with my config? What should I change to make sure that data will be parsed properly?  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 19, 2019, 12:59pm UTC](https://discuss.elastic.co/t/getting-split-type-failure-while-splitting-xml-not-sure-why-but-records-are-processed/177608/2 "2019-04-19T12:59:28Z")

</div>

You should be seeing error messages in the logstash log

```
Only String and Array types are splittable. field:[theXML][PANEL][0][DUT][GROUP][0] is of type = Hash

```

This one only applies to Main\_2

```
Only String and Array types are splittable. field:[theXML][PANEL][0][DUT][GROUP][0][GROUP][TEST] is of type = NilClass
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2019, 12:59pm UTC](https://discuss.elastic.co/t/getting-split-type-failure-while-splitting-xml-not-sure-why-but-records-are-processed/177608/3 "2019-05-17T12:59:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
