# Ingesting XML data from UDP input plugin thru elasticsearch output plugin

**URL:** <https://discuss.elastic.co/t/ingesting-xml-data-from-udp-input-plugin-thru-elasticsearch-output-plugin/377125>\
**Category:** Logstash\
**Created:** [April 14, 2025, 10:26pm UTC](https://discuss.elastic.co/t/ingesting-xml-data-from-udp-input-plugin-thru-elasticsearch-output-plugin/377125 "2025-04-14T22:26:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Francesco\_Esposito](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/francesco_esposito/32/141865_2.png) [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Post date:** [April 14, 2025, 10:26pm UTC](https://discuss.elastic.co/t/ingesting-xml-data-from-udp-input-plugin-thru-elasticsearch-output-plugin/377125/1 "2025-04-14T22:26:40Z")

</div>

Hello everyone, I need to ingest an XML received over UDP input plugin. The output plugin needs to be "elasticsearch". This is an example of XML:

```auto
<EVENT>
	<HOST>FRANCESCOE-RMT</HOST>
	<INSTANCEID>3C38C41D-9F66-47AB-AF8D-582A4BBEDD0D</INSTANCEID>
	<APPLICATION>TESTUDPLOGGER</APPLICATION>
	<THREADID>20172</THREADID>
	<APPVERSION>1.0.1.11</APPVERSION>
	<LINENO>1</LINENO>
	<EVENTSEQNO>1</EVENTSEQNO>
	<EVENTDATETIME>04/14/2025 14:11:24:977</EVENTDATETIME>
	<SEVERITY>0</SEVERITY>
	<EVENTNAME>TestEvent1 04/14/2025 14:11:24:11</EVENTNAME>
	<EVENTINFO>04/14/2025 14:11:24:11benfranksue</EVENTINFO>
</EVENT>

```

So, my approach is to try to translate this XML in a JSON. All the fields inside need to become json fields.

I am starting try to save the data received to a file, thinking that when I will be able to have a json compatible with my index, elasticsearch output plugin will be able to process it.

How would you guys configure that? Am I on the right track?

```auto
input {
	udp {
		port => 517
	}
}
filter {
??????
}
output {
	file {
		path => "/log_streaming/my_app/records/log-%{+yyyy-MM-dd_HH.mm.ss.SSS}.log"	
		codec => line { format => "%{message}" }
	}
}

```

---

<div class="post-metadata">

**Author:** ![Francesco\_Esposito](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/francesco_esposito/32/141865_2.png) [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Post date:** [April 14, 2025, 11:51pm UTC](https://discuss.elastic.co/t/ingesting-xml-data-from-udp-input-plugin-thru-elasticsearch-output-plugin/377125/2 "2025-04-14T23:51:21Z")

</div>

I think I made it with this:

```auto
input {
	udp {
		port => 517
	}
}
filter {
	xml {
		force_array => false
		source => "message"
		target => "myxml"
	}
}
output {
	file {
		path => "/log_streaming/my_app/records/log-%{+yyyy-MM-dd_HH.mm.ss.SSS}.log"	
		codec => line { format => "%{myxml}" }
	}
}

```
