# Indexing many xml files

**URL:** <https://discuss.elastic.co/t/indexing-many-xml-files/56420>\
**Category:** Logstash\
**Created:** [July 26, 2016, 4:33pm UTC](https://discuss.elastic.co/t/indexing-many-xml-files/56420 "2016-07-26T16:33:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mark.demichele](https://avatars.discourse-cdn.com/v4/letter/m/8baadc/32.png) [@mark.demichele](https://discuss.elastic.co/u/mark.demichele)\
**Post date:** [July 26, 2016, 4:33pm UTC](https://discuss.elastic.co/t/indexing-many-xml-files/56420/1 "2016-07-26T16:33:47Z")

</div>

I have an application that maintains many xml files under a folder and set of sub-folders. The xml files are added and removed from these folders. Is there a way to use logstash to send these files to Elastic Search allowing users to search through them. We would also need to remove them from elastic search when they get removed from the folders.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 27, 2016, 1:25pm UTC](https://discuss.elastic.co/t/indexing-many-xml-files/56420/2 "2016-07-27T13:25:41Z")

</div>

Sure, that's possible with the file input. Just use a filename pattern that selects all possible XML files. You'll have to use a multiline codec to join the lines of each XML file into a single events. This is a bit clunky.

However, to remove the documents from ES once the XML files are gone is something you'll have to do outside of Logstash (or with a custom plugin).

---

<div class="post-metadata">

**Author:** ![mark.demichele](https://avatars.discourse-cdn.com/v4/letter/m/8baadc/32.png) [@mark.demichele](https://discuss.elastic.co/u/mark.demichele)\
**Post date:** [August 12, 2016, 5:21pm UTC](https://discuss.elastic.co/t/indexing-many-xml-files/56420/3 "2016-08-12T17:21:50Z")

</div>

What if a file changes. Will the record in elastic search get replaced, or will I get two?

I'm trying to replace an antiquated installation of Microsoft Indexing Service. We have it set up to just monitor a folder structure and it just "works" and indexes what's there. It seems to handle add, updates and deletes all on it's own.

Is there anyway to easily get and ELK stack to do this?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 14, 2016, 1:54pm UTC](https://discuss.elastic.co/t/indexing-many-xml-files/56420/4 "2016-08-14T13:54:07Z")

</div>

> What if a file changes. Will the record in Elasticsearch get replaced, or will I get two?

(...or will nothing happen at all?) It depends on _how_ the file is updated. Is it updated in place, i.e. is the same inode (or equivalent) reused, or is it replaced with a new file that happens to have the same name? The primary purpose of the file input is to monitor log files. Once you deviate from that use case things will get bumpy.

> I'm trying to replace an antiquated installation of Microsoft Indexing Service. We have it set up to just monitor a folder structure and it just "works" and indexes what's there. It seems to handle add, updates and deletes all on it's own.

As it should, being an indexing service and all. Logstash doesn't do this well out of the box (but writing a plugin that does it wouldn't be too hard). You should probably look into [GitHub - dadoonet/fscrawler: Elasticsearch File System Crawler (FS Crawler)](https://github.com/dadoonet/fscrawler) and similar helpers.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:43am UTC](https://discuss.elastic.co/t/indexing-many-xml-files/56420/5 "2017-07-06T04:43:34Z")

</div>


