# How to use grok filter on XML field

**URL:** <https://discuss.elastic.co/t/how-to-use-grok-filter-on-xml-field/181718>\
**Category:** Logstash\
**Created:** [May 19, 2019, 6:59pm UTC](https://discuss.elastic.co/t/how-to-use-grok-filter-on-xml-field/181718 "2019-05-19T18:59:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yoav\_Ben\_Moha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoav_ben_moha/32/46202_2.png) [@Yoav\_Ben\_Moha](https://discuss.elastic.co/u/Yoav_Ben_Moha)\
**Post date:** [May 19, 2019, 6:59pm UTC](https://discuss.elastic.co/t/how-to-use-grok-filter-on-xml-field/181718/1 "2019-05-19T18:59:26Z")

</div>

Hi,  
I have a csv files .  
One of the fields has an xml strutcher.  
I need to return the value that exists between the first apperence of :   
In this case i need to return : 0-GOLD

`<SVC ID="0" SUCC="1"><PLCY><PLAN>0-GOLD</PLAN><PLAN>0-GOLD</PLAN><PLAN>NEW_SPECIAL</PLAN><PLAN>MIN-MAX FILTER</PLAN><PLAN>CARRIER CHECK IN</PLAN><PLAN>0-GOLD SPLIT</PLAN></PLCY><Time>2018-10-22+05:31:14.270</Time></SVC>`

Please advise how to do it .....

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 19, 2019, 10:01pm UTC](https://discuss.elastic.co/t/how-to-use-grok-filter-on-xml-field/181718/2 "2019-05-19T22:01:51Z")

</div>

Please edit your post, select the data, and click on \</\> in the toolbar above the edit pane, and make sure the data appears correct in the preview pane on the right.

If you have xml I would start with an xml filter.

---

<div class="post-metadata">

**Author:** ![Yoav\_Ben\_Moha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoav_ben_moha/32/46202_2.png) [@Yoav\_Ben\_Moha](https://discuss.elastic.co/u/Yoav_Ben_Moha)\
**Post date:** [May 21, 2019, 7:35pm UTC](https://discuss.elastic.co/t/how-to-use-grok-filter-on-xml-field/181718/3 "2019-05-21T19:35:02Z")

</div>

Hi

> [@Badger](#):
>
> If you have xml I would start with an xml filter

Can please advise how ? Can you share an example ?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 21, 2019, 9:25pm UTC](https://discuss.elastic.co/t/how-to-use-grok-filter-on-xml-field/181718/4 "2019-05-21T21:25:56Z")

</div>

> [@Yoav\_Ben\_Moha](#):
>
> Can you share an example ?

```
xml { source => "message" target => "theXML" }
mutate { copy => { "[theXML][PLCY][0][PLAN][0]" => "someField" } }

```

---

<div class="post-metadata">

**Author:** ![Yoav\_Ben\_Moha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yoav_ben_moha/32/46202_2.png) [@Yoav\_Ben\_Moha](https://discuss.elastic.co/u/Yoav_Ben_Moha)\
**Post date:** [May 23, 2019, 1:12pm UTC](https://discuss.elastic.co/t/how-to-use-grok-filter-on-xml-field/181718/5 "2019-05-23T13:12:33Z")

</div>

The latest example was releay helpful.  
I was wonder if you can advise how to return only the first element in the Array.

The xml:  
`<SVC ID="0" SUCC="1"><PLCY><PLAN>0-GOLD</PLAN><PLAN>0-GOLD</PLAN><PLAN>NEW_SPECIAL</PLAN><PLAN>MIN-MAX FILTER</PLAN><PLAN>CARRIER CHECK IN</PLAN><PLAN>0-GOLD SPLIT</PLAN></PLCY><Time>2018-10-22+05:31:14.270</Time></SVC>`

The program:

> ```
> xml { source => "message" target => "theXML" }
> mutate { copy => { "[theXML][PLCY][0][PLAN][0]" => "someField" } }
> 
> ```

The result:

```
"theXML" => {
        "SUCC" => "1",
        "PLCY" => [
            [0] {
                "PLAN" => [
                    [0] "0-GOLD",
                    [1] "0-GOLD",
                    [2] "NEW_SPECIAL",
                    [3] "MIN-MAX FILTER"
                    .... 
                ]
            }

```

1. I would like to assign into =\> "someField" , only the first element : 0-GOLD
2. Can you advise on a link to documentation that explain how you build the statment above ?

Thanks alot for your help !

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 23, 2019, 1:34pm UTC](https://discuss.elastic.co/t/how-to-use-grok-filter-on-xml-field/181718/6 "2019-05-23T13:34:33Z")

</div>

> [@Yoav\_Ben\_Moha](#):
>
> I was wonder if you can advise how to return only the first element in the Array.

That is what the second line of my example does.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2019, 1:34pm UTC](https://discuss.elastic.co/t/how-to-use-grok-filter-on-xml-field/181718/7 "2019-06-20T13:34:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
