# Inputting XML from File (Windows)

**URL:** <https://discuss.elastic.co/t/inputting-xml-from-file-windows/287513>\
**Category:** Logstash\
**Created:** [October 24, 2021, 3:45pm UTC](https://discuss.elastic.co/t/inputting-xml-from-file-windows/287513 "2021-10-24T15:45:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tim\_Mobley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_mobley/32/94741_2.png) [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Post date:** [October 24, 2021, 3:45pm UTC](https://discuss.elastic.co/t/inputting-xml-from-file-windows/287513/1 "2021-10-24T15:45:41Z")

</div>

I am attempting to use the File input plugin to ingest XML into Logstash running on a Windows host. At this point, I just want to verify that the input section of the pipeline is working. Here is the input section of my pipeline config:

```auto
input {
  file {
    path => ["C:\temp\SCAP\*.xml"]
  }
}

```

And here is the what I see in the **logstash-plain.log** :

```auto
[2021-10-24T11:23:49,953][INFO][logstash.inputs.file][scap-results] No sincedb_path set, generating one based on the "path" setting {:sincedb_path=>"P:/Elastic/Logstash/logstash-7.14.1/data/plugins/inputs/file/.sincedb_24f630408b5fe29cf9ccb9e55db97036", :path=>["C:\\temp\\SCAP\\*.xml"]}

```

Other than this, I don't see any ERROR or WARN logs. The part I'm wanting to confirm is that it is reading the path correctly. Examples of the [path array](https://www.elastic.co/guide/en/logstash/current/configuration-file-structure.html#list) are for Linux, so I am not sure if I should make the slashes '/' or '' in Windows or escape them. The same documentation shows '\*' for globbing, so I assume this would work for Windows as well, but if I could get a second opinion, that'd be great.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 24, 2021, 3:56pm UTC](https://discuss.elastic.co/t/inputting-xml-from-file-windows/287513/2 "2021-10-24T15:56:39Z")

</div>

You are missing the `start_position => "beginning"` in your `file` input, without it logstash will start reading your file from the end, which means only when new events are written to that file.

Not sure if you need to change the slashes to forward slashes as I do not use windows, but I know that filebeat has some issues if you are not using forward slashes.

Try this:

```auto
input {
  file {
    path => ["C:\temp\SCAP\*.xml"]
    start_position => "beginning"
  }
}

```

Also, you will need to delete this file to make logstash read your source file again:

```auto
P:/Elastic/Logstash/logstash-7.14.1/data/plugins/inputs/file/.sincedb_24f630408b5fe29cf9ccb9e55db97036

```

If you want, you can use `sincedb_path => "NUL"` in the `file` input to force logstash to always reread files when started.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 24, 2021, 4:40pm UTC](https://discuss.elastic.co/t/inputting-xml-from-file-windows/287513/3 "2021-10-24T16:40:26Z")

</div>

Do not use backslash in the path option of a file input, they are treated as escapes. Use / or \\.

---

<div class="post-metadata">

**Author:** ![Tim\_Mobley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_mobley/32/94741_2.png) [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Post date:** [October 24, 2021, 6:39pm UTC](https://discuss.elastic.co/t/inputting-xml-from-file-windows/287513/4 "2021-10-24T18:39:33Z")

</div>

Thank you both for your replies. @leandrojmp your suggestion of adding the start\_position setting did the trick. I also changed the slash direction as @Badger suggested.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2021, 6:39pm UTC](https://discuss.elastic.co/t/inputting-xml-from-file-windows/287513/5 "2021-11-21T18:39:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
