# Help parsing Xml File

**URL:** <https://discuss.elastic.co/t/help-parsing-xml-file/152538>\
**Category:** Logstash\
**Created:** [October 15, 2018, 5:06pm UTC](https://discuss.elastic.co/t/help-parsing-xml-file/152538 "2018-10-15T17:06:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![L-Luciano](https://avatars.discourse-cdn.com/v4/letter/l/ea5d25/32.png) [@L-Luciano](https://discuss.elastic.co/u/L-Luciano)\
**Post date:** [October 15, 2018, 5:06pm UTC](https://discuss.elastic.co/t/help-parsing-xml-file/152538/1 "2018-10-15T17:06:33Z")

</div>

Hello,

I tried to format my xml in ES.

Xml Format :

```
<PlaceList xmlns="http://places.maps.here.com/pds">
        <Place xmlns="http://places.maps.here.com/pds">
            <Identity isDeleted="false" lastUpdatedTimeStamp="2018-09-02T21:45:09.677Z">
                <PlaceId>250u03q7-235079d2a6cf494498fd36608f3cf81d</PlaceId>
                <QualityLevel>5</QualityLevel>
            </Identity>
        </Place>
        <Place xmlns="http://places.maps.here.com/pds">
            <Identity isDeleted="false" lastUpdatedTimeStamp="2018-09-23T06:30:00.974Z">
                <PlaceId>250spg6q-f9672d4b2c1f41209cd2f038d26a93ef</PlaceId>
                <QualityLevel>4</QualityLevel>             
            </Identity>
        </Place>
    </PlaceList>

```

I tried with config :

```
input { {
    file
    {
    codec => multiline 
                {
                  pattern => "<PlaceList>" 
                  negate => "true"
                  what => "previous"
                }
            }}

filter {
          xml {
            source => "message"
            store_xml => "false"
            xpath => ["/PlaceList//Place", "places"]    
          }

split {
            field => "places"
          }

xml {
            source => "places"
            store_xml => "false"
            xpath => ["/Place/Identity/PlaceId/text()", "place_id"]
            remove_field => ["places"]
          }
        }

```

It's failed if i use the split : field:places is of type = NilClass.

If I comment the split and the last xml, I have no result,

The "message" field contains well the xml from beginning to the end.

Lucio

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [October 24, 2018, 9:42pm UTC](https://discuss.elastic.co/t/help-parsing-xml-file/152538/2 "2018-10-24T21:42:38Z")

</div>

Interesting, never thought to "stack" the XML filter. Try changing your first XML config to the below, see what that gets you:

```
xml {
  source => "message"
  store_xml => "false"
  xpath => ["/PlaceList/Place/text()", "places"]
}

```

I feel like that is still going to throw some sort of error though. If the PlaceList node isn't necessary, you could modify your multiline codec to stick everything matching `<place` on the same line instead and then use that as your root node in the XML pathing.

---

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [October 25, 2018, 4:33am UTC](https://discuss.elastic.co/t/help-parsing-xml-file/152538/3 "2018-10-25T04:33:12Z")

</div>

hope this helps you,

> [@Is it possible to change output structure](https://discuss.elastic.co/t/is-it-possible-to-change-output-structure/153759/6):
>
> The xml file which you have posted has an error, didnot close the tag \<tag pluginname="LastUnauthenticatedResults"\>1539\</tag\> The input code is as follows as per your requirement, input { file { path =\> "D:/xxxxx/ELKStack/sample.xml" start\_position =\> "beginning" sincedb\_path =\> "NUL" codec =\> multiline { pattern =\> "" negate =\> "true" what =\> "previous" auto\_flush\_interval =\> 1 max\_lines =\> 333333 } } } filter { xml { source =\> "message" target =\> "parsed" store\_xml =\> "fal…

---

<div class="post-metadata">

**Author:** ![L-Luciano](https://avatars.discourse-cdn.com/v4/letter/l/ea5d25/32.png) [@L-Luciano](https://discuss.elastic.co/u/L-Luciano)\
**Post date:** [October 25, 2018, 7:53am UTC](https://discuss.elastic.co/t/help-parsing-xml-file/152538/4 "2018-10-25T07:53:32Z")

</div>

The pb was the xmlns attribute. I had to add the namespace.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2018, 8:02am UTC](https://discuss.elastic.co/t/help-parsing-xml-file/152538/5 "2018-11-22T08:02:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
