# How to add\_field and covert field type while parsing nested xml

**URL:** <https://discuss.elastic.co/t/how-to-add-field-and-covert-field-type-while-parsing-nested-xml/2134>\
**Category:** Logstash\
**Created:** [June 8, 2015, 1:23pm UTC](https://discuss.elastic.co/t/how-to-add-field-and-covert-field-type-while-parsing-nested-xml/2134 "2015-06-08T13:23:56Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saket\_Kumar](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)\
**Post date:** [June 8, 2015, 1:23pm UTC](https://discuss.elastic.co/t/how-to-add-field-and-covert-field-type-while-parsing-nested-xml/2134/1 "2015-06-08T13:23:56Z")

</div>

\<?root\> \<?fields1\> \<?fields1.1\> \<?fields1.1.1\> \<?fielda\>...\<?/fielda\> \<?fieldb\>...\<?/fieldb\> ..... Requirement is something like i would like add field with custom name add\_field =\> { custom\_field\_name =\> "%{[root][fields1][fields1.1][fielda]}" custom\_field\_name =\> "%{[root][fields1][fields1.1][fielda]}" } Also, mutate {convert =\> ["root.fields1.fields1.1.fielda", "integer"]} I tried both the way but didnt get success. Is it correct way to config. Thanks

---

<div class="post-metadata">

**Author:** ![Saket\_Kumar](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)\
**Post date:** [June 9, 2015, 5:28am UTC](https://discuss.elastic.co/t/how-to-add-field-and-covert-field-type-while-parsing-nested-xml/2134/2 "2015-06-09T05:28:13Z")

</div>

Any help is much appreciated!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 9, 2015, 5:38am UTC](https://discuss.elastic.co/t/how-to-add-field-and-covert-field-type-while-parsing-nested-xml/2134/3 "2015-06-09T05:38:31Z")

</div>

Are you able to parse the XML correctly? What do your messages look like right now?

---

<div class="post-metadata">

**Author:** ![Saket\_Kumar](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)\
**Post date:** [June 9, 2015, 5:44am UTC](https://discuss.elastic.co/t/how-to-add-field-and-covert-field-type-while-parsing-nested-xml/2134/4 "2015-06-09T05:44:07Z")

</div>

Yes now by replacing Logstash from 1.5.0 rc3 to 1.5.0 the exception is eradicated. Found on forum that error is fixed in higher version.

message looks like....  
{"message":"\<?xml version=\"1.0\" encoding=\"UTF-8\"?\>\n\n200\nOk\n1\n\n150603\_VD\_9VJ\n1009017\n979560\n17\n61\n\n","@version":"1","@timestamp":"2015-06-08T08:38:50.056Z","host":"mac109","path":"/opt/Log/new7.xml","tags":["multiline","\_xmlparsefailure"],"data":{"statusCode":["200"],"statusText":["Ok"],"requestId":["1"],"data":[{"testId":["150603\_VD\_9VJ"],"bytesIn":["1009017"],"bytesInDoc":["979560"],"connections":["17"],"requests":["61"]}]}}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 9, 2015, 6:08am UTC](https://discuss.elastic.co/t/how-to-add-field-and-covert-field-type-while-parsing-nested-xml/2134/5 "2015-06-09T06:08:04Z")

</div>

I don't know exactly what output you want, but this extracts the testId and bytesIn fields into top-level fields and converts the latter to an integer:

```
mutate {
  add_field => {
    "test_id" => "%{[data][0][testId][0]}"
    "bytes_in" => "%{[data][0][bytesIn][0]}"
  }
}
mutate {
  convert => ["bytes_in", "integer"]
}
```

---

<div class="post-metadata">

**Author:** ![Saket\_Kumar](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)\
**Post date:** [June 9, 2015, 6:13am UTC](https://discuss.elastic.co/t/how-to-add-field-and-covert-field-type-while-parsing-nested-xml/2134/6 "2015-06-09T06:13:59Z")

</div>

Thanks magnus! i was expecting same to understand how would I be refering fieldarray...  
thanks for your help...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:38am UTC](https://discuss.elastic.co/t/how-to-add-field-and-covert-field-type-while-parsing-nested-xml/2134/7 "2017-07-06T05:38:05Z")

</div>


