# How to decode html file in heartbeat/filebeat

**URL:** <https://discuss.elastic.co/t/how-to-decode-html-file-in-heartbeat-filebeat/306232>\
**Category:** Beats\
**Tags:** filebeat, heartbeat\
**Created:** [June 2, 2022, 1:12pm UTC](https://discuss.elastic.co/t/how-to-decode-html-file-in-heartbeat-filebeat/306232 "2022-06-02T13:12:43Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anagha\_nambiar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anagha_nambiar/32/97593_2.png) [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Post date:** [June 2, 2022, 1:12pm UTC](https://discuss.elastic.co/t/how-to-decode-html-file-in-heartbeat-filebeat/306232/1 "2022-06-02T13:12:43Z")

</div>

Hi All,

I have tried decoding XML file using decode\_xml processor in both heartbeat and filebeat and it worked as expected.  
Now I would like to decode html file. I didn't find a way to do that.

Could you please suggest a method?

Thanks

---

<div class="post-metadata">

**Author:** ![Anagha\_nambiar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anagha_nambiar/32/97593_2.png) [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Post date:** [June 2, 2022, 5:02pm UTC](https://discuss.elastic.co/t/how-to-decode-html-file-in-heartbeat-filebeat/306232/2 "2022-06-02T17:02:20Z")

</div>

Any help on this please?

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [June 2, 2022, 5:35pm UTC](https://discuss.elastic.co/t/how-to-decode-html-file-in-heartbeat-filebeat/306232/3 "2022-06-02T17:35:58Z")

</div>

What's the purpose of decoding an HTML file using a beat ?  
Is it a search use case or anything else very specific ?

---

<div class="post-metadata">

**Author:** ![Anagha\_nambiar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anagha_nambiar/32/97593_2.png) [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Post date:** [June 2, 2022, 6:06pm UTC](https://discuss.elastic.co/t/how-to-decode-html-file-in-heartbeat-filebeat/306232/4 "2022-06-02T18:06:22Z")

</div>

There is a date value which I need to get from that html response. Basically this html response is coming from a http endpoint.

For example as below:

Date:  
\<..span Id="date"\>02/06/2011\<../span\>

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [June 2, 2022, 6:24pm UTC](https://discuss.elastic.co/t/how-to-decode-html-file-in-heartbeat-filebeat/306232/5 "2022-06-02T18:24:23Z")

</div>

May be try to use dissect processor at the edge level

> **[Dissect strings | Filebeat Reference \[8.2\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/dissect.html)**

Or the grok processor at the ingest node level

> **[Grok processor | Elasticsearch Guide \[8.2\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/grok-processor.html)**

---

<div class="post-metadata">

**Author:** ![Anagha\_nambiar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anagha_nambiar/32/97593_2.png) [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Post date:** [June 2, 2022, 6:33pm UTC](https://discuss.elastic.co/t/how-to-decode-html-file-in-heartbeat-filebeat/306232/6 "2022-06-02T18:33:32Z")

</div>

Okay, I will try this and confirm back

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2022, 1:25pm UTC](https://discuss.elastic.co/t/how-to-decode-html-file-in-heartbeat-filebeat/306232/8 "2022-07-03T13:25:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
