# Ingest xml file using Logstash

**URL:** <https://discuss.elastic.co/t/ingest-xml-file-using-logstash/255113>\
**Category:** Logstash\
**Created:** [November 11, 2020, 6:34pm UTC](https://discuss.elastic.co/t/ingest-xml-file-using-logstash/255113 "2020-11-11T18:34:19Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 11, 2020, 8:00pm UTC](https://discuss.elastic.co/t/ingest-xml-file-using-logstash/255113/4 "2020-11-11T20:00:09Z")

</div>

If you want to consume the entire file as a single event then you can do something like [this](https://discuss.elastic.co/t/append-metadata-to-every-event-in-xml-file-being-ingested-to-elasticsearch/165914/2).

If your file contains multiple XML documents you must consume them separately. If they all start with `<control` then your multiline codec should be

```
codec => multiline {
    pattern=>"^<control"
    negate => "true"
    what => "previous"
    auto_flush_interval => 1
    max_lines => 3000
}

```

If you want to parse the entire message then just use

```
xml { source => "message" store_xml => true target => "theXML" }

```

If you need specific elements from the document you can use the xpath option instead of setting store\_xml.

The xml filter typically just works. The hard part is tweaking the multiline codec so that each event contains a complete XML document.

---

_[View the full topic](https://discuss.elastic.co/t/ingest-xml-file-using-logstash/255113)._
