# I am facing some issues while trying to parse XML from some host by using port without XML,

**URL:** <https://discuss.elastic.co/t/i-am-facing-some-issues-while-trying-to-parse-xml-from-some-host-by-using-port-without-xml/239733>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 3, 2020, 6:06am UTC](https://discuss.elastic.co/t/i-am-facing-some-issues-while-trying-to-parse-xml-from-some-host-by-using-port-without-xml/239733 "2020-07-03T06:06:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Radha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/radha/32/48088_2.png) [@Radha](https://discuss.elastic.co/u/Radha)\
**Post date:** [July 3, 2020, 6:06am UTC](https://discuss.elastic.co/t/i-am-facing-some-issues-while-trying-to-parse-xml-from-some-host-by-using-port-without-xml/239733/1 "2020-07-03T06:06:54Z")

</div>

filbeat yml file created:

- type: log  
paths:

sample.xml :

\<?xml version="1.0"?\> Tove Jani Reminder Don't forget me this weekend!

logstash conf file

input{  
beats {  
port =\> "5071"  
}  
}

filter {  
if [source] =~/sample/  
{  
mutate {  
add\_field =\> {  
"name" =\> "xml\_files"  
}  
}  
xml {  
source =\> "message"  
target =\> "[theXML]"  
store\_xml =\> true  
remove\_namespaces =\> true  
force\_array =\> false  
remove\_field =\> ["message"]  
}  
ruby {  
path =\> "rubypath/split\_fields.rb"  
script\_params =\> { field =\> "[theXML][disk]" target =\> "theXML"}

```
    }

            }

```

}

output {  
stdout{  
codec =\> rubydebug  
}  
}

ruby code:  
def register(params)  
@field = params['field']  
@target = params['target']  
end

def filter(event)  
data = event.get(@field)  
event.remove(@field)  
a =   
data.each { |x|  
e = event.clone  
e.set(@target, x)  
a \<\< e  
}  
a  
end

Not able to push them to Elasticsearch & kibana even though we have set correct ports:

[WARN] 2020-07-03 02:04:22.398 [[main]\>worker0] xml - Error parsing xml with XmlSimple {:source=\>"message", :value=\>"\<?xml version=\"1.0\"?\>\n\nTove\nJani\nReminder\nDon't forget me this weekend!", :exception=\>#\<REXML::ParseException: No close tag for /note  
Line: 6  
Position: 131  
Last 80 unconsumed characters:

> , :backtrace=\>["uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/rexml/parsers/treeparser.rb:28:in `parse'", "uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/rexml/document.rb:288:in `build'", "uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/rexml/document.rb:45:in `initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/xml-simple-1.1.5/lib/xmlsimple.rb:971:in `parse'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/xml-simple-1.1.5/lib/xmlsimple.rb:164:in `xml_in'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/xml-simple-1.1.5/lib/xmlsimple.rb:203:in `xml\_in'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-xml-4.0.7/lib/logstash/filters/xml.rb:185:in `filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:143:in `do\_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:162:in `block in multi_filter'", "org/jruby/RubyArray.java:1814:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:159:in `multi_filter'", "org/logstash/config/ir/compiler/AbstractFilterDelegatorExt.java:115:in `multi\_filter'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:262:in `block in start\_workers'"]}  
> [ERROR] 2020-07-03 02:04:22.447 [[main]\>worker0] ruby - Could not process event: undefined method `each' for nil:NilClass {:script_path=\>"/etc/logstash/conf.d/split_fields.rb", :class=\>"NoMethodError", :backtrace=\>["/etc/logstash/conf.d/split_fields.rb:10:in `filter'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-ruby-3.1.5/lib/logstash/filters/ruby/script/context.rb:55:in `execute_filter'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-ruby-3.1.5/lib/logstash/filters/ruby/script.rb:30:in `execute'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-ruby-3.1.5/lib/logstash/filters/ruby.rb:98:in `file_script'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-ruby-3.1.5/lib/logstash/filters/ruby.rb:84:in `filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:143:in `do_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:162:in `block in multi\_filter'", "org/jruby/RubyArray.java:1814:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:159:in `multi\_filter'", "org/logstash/config/ir/compiler/AbstractFilterDelegatorExt.java:115:in `multi_filter'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:262:in `block in start\_workers'"]}  
> {  
> "source" =\> "path\sample.xml",  
> "beat" =\> {  
> "name" =\> "XXXXXXXX",  
> "version" =\> "6.4.1",  
> "hostname" =\> "XXXXXXX"  
> },  
> "name" =\> "xml\_files",  
> "offset" =\> 0,  
> "prospector" =\> {  
> "type" =\> "log"  
> },  
> "@timestamp" =\> 2020-07-03T06:07:30.579Z,  
> "@version" =\> "1",  
> "message" =\> "\<?xml version=\"1.0\"?\>\n\nTove\nJani\nReminder\nDon't forget me this weekend!",  
> "input" =\> {  
> "type" =\> "log"  
> },  
> "tags" =\> [  
> [0] "beats\_input\_codec\_plain\_applied",  
> [1] "\_xmlparsefailure",  
> [2] "\_rubyexception"  
> ],  
> "fields" =\> {  
> "Branch" =\> "dev/juniper\0",  
> "Major\_Minor" =\> "5978\0\_0",  
> "Build\_Time" =\> "2020-06-21 09:23:37"  
> },  
> "host" =\> {  
> "name" =\> "XXXXXXXXX"  
> }  
> }

Is there any way to send whole XML as one event without XPATHS ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 3, 2020, 7:58am UTC](https://discuss.elastic.co/t/i-am-facing-some-issues-while-trying-to-parse-xml-from-some-host-by-using-port-without-xml/239733/2 "2020-07-03T07:58:17Z")

</div>

Welcome!

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2020, 9:58am UTC](https://discuss.elastic.co/t/i-am-facing-some-issues-while-trying-to-parse-xml-from-some-host-by-using-port-without-xml/239733/3 "2020-07-31T09:58:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
