How to parse and index xml in ES7

I need to index and parse xml in elasticsearsh.
I need one field to store the xml as raw data and another field that will contain a fvalue retrieved from xpath in the same xml

You can use an xml filter to parse the XML string. That supports xpath references.

I'm aware that such filter exists. Yet, the documentation is brief i couldn't build a working example from it . Can you show me how i can achieve it and how dummy config file would look like ?
Thanks :slight_smile:

Can you share a sample XML and field and what you are trying to parse?

it looks something like this :

<dataDocument xmlns="" xmlns:xsi="" fpmlVersion="5-9" xsi:schemaLocation=" ../../fpml-main-5-9.xsd ../../xmldsig-core-schema.xsd">
<partyReference href="PartyA"/>
<tradeId tradeIdScheme="">ACAVS1234567</tradeId>
<tradeDate id="TradeDate">2014-04-08</tradeDate>
<terminationDate id="TerminationDate">
<payerPartyReference href="PartyA"/>
<receiverPartyReference href="PartyB"/>
<calculationPeriodsSchedule id="varianceLegCalculationPeriodSchedule">
<!--  Note:   instrumentId is required only in Confirmation View   -->
<instrumentId instrumentIdScheme="">MOP-CFR BRAZIL-FMB</instrumentId>
<notionalAmount id="varianceLegNotionalAmount">
<!--  Note that, because this swap does not have a reinvestment feature on the notional  -->
<!--  that the 'amount' below is the notional amount for the Term                        -->
<calculationPeriodsScheduleReference href="varianceLegCalculationPeriodSchedule"/>
<party id="PartyA">
<partyId partyIdScheme="">Party_A_LEI</partyId>
<party id="PartyB">
<partyId partyIdScheme="">Party_B_LEI</partyId>

it follows fpml standard for xml .
what i'm trying to achieve is for each xml file i need one document in ES that will contain the entire file as a string in one field and its id will be one field that is inside the xml :

perhaps like this:

id: " some field from the xml for the sake of the example let's say it will be tradeId",
xml:" will contain the entire xml as a string"


There is an example of an xml filter using xpath here.

i have previously worked with similar instructions , the thread you're referencing contains an error that i also encountered as well ( "Last 80 unconsumed characters:" )

That means your "XML" is not valid XML. There should be an exception logged telling you why. For example, in that thread it is ":exception=>#<REXML::ParseException: No close tag for /NewData".

If you XML is spread across multiple lines you will need to combine them into a single event. If you are using a file input a multiline codec may do the job. What does your input configuration look like?

like this:

input {
  file {
    path => "C:/Users/user/Documents/shareCommon/pocc.xml"
    start_position => beginning
    sincedb_path => "nul"
    type => "xml"
    codec => multiline {

        pattern => "^<?FpML.*>"
        charset => "ISO-8859-1"
        negate => "true"
        what => "previous"
        max_lines => 100000

filter {
    xml {
        source => "message"
        target => "doc"
        store_xml => true
        xpath => ["/FpML/party/partyId/text()","fpml"]


output {

  stdout {
    codec => rubydebug

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.