# Handle nested xml file with logstash and ruby script

**URL:** <https://discuss.elastic.co/t/handle-nested-xml-file-with-logstash-and-ruby-script/153603>\
**Category:** Logstash\
**Created:** [October 23, 2018, 1:06pm UTC](https://discuss.elastic.co/t/handle-nested-xml-file-with-logstash-and-ruby-script/153603 "2018-10-23T13:06:30Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [October 25, 2018, 6:45am UTC](https://discuss.elastic.co/t/handle-nested-xml-file-with-logstash-and-ruby-script/153603/4 "2018-10-25T06:45:53Z")

</div>

Hello humalog,

You can extend the below code to get the output required,

> [@Is it possible to change output structure](https://discuss.elastic.co/t/is-it-possible-to-change-output-structure/153759/6):
>
> The xml file which you have posted has an error, didnot close the tag \<tag pluginname="LastUnauthenticatedResults"\>1539\</tag\> The input code is as follows as per your requirement, input { file { path =\> "D:/xxxxx/ELKStack/sample.xml" start\_position =\> "beginning" sincedb\_path =\> "NUL" codec =\> multiline { pattern =\> "" negate =\> "true" what =\> "previous" auto\_flush\_interval =\> 1 max\_lines =\> 333333 } } } filter { xml { source =\> "message" target =\> "parsed" store\_xml =\> "fal…

---

_[View the full topic](https://discuss.elastic.co/t/handle-nested-xml-file-with-logstash-and-ruby-script/153603)._
