# How to split xml into different events

**URL:** <https://discuss.elastic.co/t/how-to-split-xml-into-different-events/203039>\
**Category:** Logstash\
**Created:** [October 10, 2019, 1:54pm UTC](https://discuss.elastic.co/t/how-to-split-xml-into-different-events/203039 "2019-10-10T13:54:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![griffer98](https://avatars.discourse-cdn.com/v4/letter/g/e8c25b/32.png) [@griffer98](https://discuss.elastic.co/u/griffer98)\
**Post date:** [October 10, 2019, 1:54pm UTC](https://discuss.elastic.co/t/how-to-split-xml-into-different-events/203039/1 "2019-10-10T13:54:25Z")

</div>

I am trying to take certain parts of an xml document and split it into different events that I can look at separately in Kibana. Here is a sample xml document here.

```
<?xml version="1.0"?>
<Report>
	<company>some company</company>
	<address>some address</address>
	<employees>
		<file>
			<name>Bill Smith</name>
			<position>Crew Member</position>
		</file>
		<file>
			<name>John Doe</name>
			<position>General Manager</position>
		</file>
	</employees>
</Report>

```

I would like to get 3 different events out of this. One event that has the beginning tags. company and address. and two other ones which each contain the tags within the file tag, so two other events each with name and position. Also if possible, each of the two events would ideally also have the information from the first event.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 10, 2019, 3:57pm UTC](https://discuss.elastic.co/t/how-to-split-xml-into-different-events/203039/2 "2019-10-10T15:57:36Z")

</div>

The employees elements will become an array, so you can use a split filter to split that to get one event per employee. You can create an additional event for the company using a clone filter.

```
    xml { source => "message" target => "theXML" force_array => false remove_field => ["message"] }
    clone { clones => ["company"] }
    if [type] == "company" {
        mutate { remove_field => ["[theXML][employees]" ] }
    } else {
        split { field => "[theXML][employees][file]" }
    }
```

---

<div class="post-metadata">

**Author:** ![griffer98](https://avatars.discourse-cdn.com/v4/letter/g/e8c25b/32.png) [@griffer98](https://discuss.elastic.co/u/griffer98)\
**Post date:** [October 10, 2019, 7:10pm UTC](https://discuss.elastic.co/t/how-to-split-xml-into-different-events/203039/3 "2019-10-10T19:10:47Z")

</div>

This didnt work. When I look in discover in kibana, it is still showing it as 1 event.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2019, 7:10pm UTC](https://discuss.elastic.co/t/how-to-split-xml-into-different-events/203039/4 "2019-11-07T19:10:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
