# How to read XML format within a .log file

**URL:** <https://discuss.elastic.co/t/how-to-read-xml-format-within-a-log-file/119999>\
**Category:** Logstash\
**Created:** [February 15, 2018, 2:14pm UTC](https://discuss.elastic.co/t/how-to-read-xml-format-within-a-log-file/119999 "2018-02-15T14:14:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![garcesdavid](https://avatars.discourse-cdn.com/v4/letter/g/35a633/32.png) [@garcesdavid](https://discuss.elastic.co/u/garcesdavid)\
**Post date:** [February 15, 2018, 2:14pm UTC](https://discuss.elastic.co/t/how-to-read-xml-format-within-a-log-file/119999/1 "2018-02-15T14:14:16Z")

</div>

Hi all 🙂

I have an app that writes XML format in a .log file per transaction it receive.  
So basically, this is the XML format:

```
<Bnx>
    <HEADER orig="9eb23c4d0a05e60a210200ce00000626" App="3" IdServ="test" IdTran="test" OpeDate="Thu Dec 28 14:56:09 COT 2017" Lang="EN" />
    <BnxChild>
        <BnxDescription>
            <medetail>test</medetail>
            <tedetail>example</tedetail>
            <rrndetail>123</rrndetail>|
            <lodetail>500</lodetail>
            <docdetail>6</docdetail>
            <date_detail>2017-09-27</date_detail>
            <hour_detail>14:20:00</hour_detail>
            <dec_detail>1.50</dec_detail>
        </BnxDescription>
    </BnxChild>
</Bnx>

```

And here is my logstash's .config file:

input {  
file {  
path =\> "/path/to/file/example.log"  
start\_position =\> "beginning"  
type =\> "bnxdata"  
codec =\> multiline {  
pattern =\> "\</Bnx\>"  
negate =\> "true"  
what =\> "previous"  
multiline\_tag =\> "test\_multiTag"  
max\_lines =\> 1000  
auto\_flush\_interval =\> 1  
}  
}  
}

filter {  
if [type] == "bnxdata" {

xml {  
source =\> "message"  
target =\> "parsed"  
add\_field =\> {  
Bnx =\> "%{[parsed][Bnx]}"  
BnxChild =\> "%{[parsed][BnxChild]}"  
}   
xpath =\> [  
"//Bnx/BnxChild/BnxDescription/@medetail/text()", "medetail",  
"//Bnx/BnxChild/BnxDescription/@tedetail/text()", "tedetail",  
"//Bnx/BnxChild/BnxDescription/@rrndetail/text()", "rrndetail",  
"//Bnx/BnxChild/BnxDescription/@lodetail/text()", "lodetail"  
]  
}

date {  
match =\> ["endTime", "yyyy-MM-dd HH:mm:ss", "ISO8601"]  
}  
}  
}

output {  
if [type] == "bnxdata" {  
stdout {codec =\> rubydebug}  
elasticsearch {  
hosts =\> ["[http://localhost:9200/](http://localhost:9200/)"]  
index =\> "auth2-%{+YYYY.MM.dd}"  
document\_type =\> "bnxdata"  
}  
}  
}

Attempting to launch logstash i'm getting the following error:

{  
"message" =\> " \n \<HEADER orig="9eb23c4d0a05e60a210200ce0  
0000626" App="3" IdServ="test" IdTran="test" OpeDate="Thu Dec 28 14:56:0  
9 COT 2017" Lang="EN" /\>\n \n \n  
test\n example\</ted  
etail\>\n 123|\n 5  
00\n 6\n \<date\_d  
etail\>2017-09-27\</date\_detail\>\n \<hour\_detail\>14:20:00\</hour\_deta  
il\>\n \<dec\_detail\>1.50\</dec\_detail\>\n \</BnxDescription

> \n ",  
> "@version" =\> "1",  
> "@timestamp" =\> 2018-02-14T20:08:12.155Z,  
> "tags" =\> [  
> [0] "test\_multiTag",  
> [1] "\_xmlparsefailure"  
> ],

Does anyone know what does it means and how can I solve it?  
Or if someone knows another appropriate way to read the XML format i'll appreciate it 😃  
-Regards

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 15, 2018, 2:53pm UTC](https://discuss.elastic.co/t/how-to-read-xml-format-within-a-log-file/119999/2 "2018-02-15T14:53:06Z")

</div>

Your multiline configuration includes everything up to _but not including_ `</Bnx>`. Does example.log contain multiple log entries or can you just slurp the whole file into a single event?

---

<div class="post-metadata">

**Author:** ![garcesdavid](https://avatars.discourse-cdn.com/v4/letter/g/35a633/32.png) [@garcesdavid](https://discuss.elastic.co/u/garcesdavid)\
**Post date:** [February 15, 2018, 2:54pm UTC](https://discuss.elastic.co/t/how-to-read-xml-format-within-a-log-file/119999/3 "2018-02-15T14:54:50Z")

</div>

Yep  
The log contains multiple xml entries.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 16, 2018, 7:24am UTC](https://discuss.elastic.co/t/how-to-read-xml-format-within-a-log-file/119999/4 "2018-02-16T07:24:37Z")

</div>

Then your multiline configuration should look like this:

```
pattern => "^<Bnx>"
negate => true
what => "previous"

```

That is, unless the current line is the first line of an XML document, merge this line with the previous line.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2018, 7:25am UTC](https://discuss.elastic.co/t/how-to-read-xml-format-within-a-log-file/119999/5 "2018-03-16T07:25:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
