# Logstash error: parsing xml file

**URL:** <https://discuss.elastic.co/t/logstash-error-parsing-xml-file/139720>\
**Category:** Logstash\
**Created:** [July 12, 2018, 9:57am UTC](https://discuss.elastic.co/t/logstash-error-parsing-xml-file/139720 "2018-07-12T09:57:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![saisimo02](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@saisimo02](https://discuss.elastic.co/u/saisimo02)\
**Post date:** [July 12, 2018, 9:57am UTC](https://discuss.elastic.co/t/logstash-error-parsing-xml-file/139720/1 "2018-07-12T09:57:34Z")

</div>

Hello,  
I am new on ELK and I need your help.  
I would like to get some information about the cpu, memory. Those informative are generated every 30 minutes.

## My xml file `<?xml version="1.0" encoding="UTF-8"?><measData><measInfo Id="SensorProcessingCounters"><measType p="1">SensorsProcessed</measType><measValue xxxxxxxxx ><r p="1">81</r></measValue></measInfo></measData>`

My logstash file.conf  
input {  
file {  
path =\> "/home/test/Desktop/data/file.xml"  
start\_position =\> beginning  
sincedb\_path =\> "/dev/null"  
codec =\> multiline  
{  
pattern =\> "|"  
negate =\> true  
what =\> "previous"  
}  
}  
}  
filter  
{  
xml {  
store\_xml =\> false  
source =\> "message"  
xpath =\>  
["//measInfo[@measInfoId="SensorProcessingCounters"]/measValue/r[@p='1']/text()", "SensorProcessingCounters"  
]  
}  
mutate{  
convert =\> {  
"SensorProcessingCounters"=\> "float"}  
}  
}  
output{  
elasticsearch  
{  
action =\> "index"  
hosts =\> ["localhost:9200"]  
index =\> "stock"  
}  
stdout{}  
}

* * *

error message  
[2018-07-12T11:16:19,253][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2018-07-12T11:16:19,973][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.3.1"}  
[2018-07-12T11:16:20,649][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, {, ,, ] at line 20, column 27 (byte 432) after filter\r\n{\r\nxml {\r\nstore\_xml =\> false\r\nsource =\> "message"\r\nxpath =\>\r\n["//measInfo[@measInfoId="", :backtrace=\>["/home/test/Desktop/logstash-6.3.1/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "/home/test/Desktop/logstash-6.3.1/logstash-core/lib/logstash/compiler.rb:50:in`compile\_graph'", "/home/test/Desktop/logstash-6.3.1/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'", "/home/test/Desktop/logstash-6.3.1/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "/home/test/Desktop/logstash-6.3.1/logstash-core/lib/logstash/pipeline.rb:49:in`initialize'", "/home/test/Desktop/logstash-6.3.1/logstash-core/lib/logstash/pipeline.rb:167:in `initialize'", "/home/test/Desktop/logstash-6.3.1/logstash-core/lib/logstash/pipeline_action/create.rb:40:in`execute'", "/home/test/Desktop/logstash-6.3.1/logstash-core/lib/logstash/agent.rb:305:in `block in converge\_state'"]}  
[2018-07-12T11:16:21,024][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 12, 2018, 3:01pm UTC](https://discuss.elastic.co/t/logstash-error-parsing-xml-file/139720/2 "2018-07-12T15:01:49Z")

</div>

Please look at the preview pane on the right when posting. Your xml is not visible. If you select it using the mouse and then click on \</\> in the toolbar above the composition window then that should fix that.

```
xpath => ["//measInfo[@measInfoId="SensorProcessingCounters"]/measValue/r[@p='1']/text()", "SensorProcessingCounters"]

```

If you have both single and double quotes then you will need to escape some of them.

---

<div class="post-metadata">

**Author:** ![saisimo02](https://avatars.discourse-cdn.com/v4/letter/s/edb3f5/32.png) [@saisimo02](https://discuss.elastic.co/u/saisimo02)\
**Post date:** [July 13, 2018, 11:32am UTC](https://discuss.elastic.co/t/logstash-error-parsing-xml-file/139720/3 "2018-07-13T11:32:32Z")

</div>

Oh thank you.  
Can someone help me to get the measVlue for each measType. Thank

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 13, 2018, 3:19pm UTC](https://discuss.elastic.co/t/logstash-error-parsing-xml-file/139720/4 "2018-07-13T15:19:39Z")

</div>

```
    xml {
        xpath => ["//measInfo[@Id='SensorProcessingCounters']/measValue/r[@p='1']/text()", "SensorProcessingCounters" ]
        source => "message"
        store_xml => false
    }
    if [SensorProcessingCounters] { mutate { replace => { "SensorProcessingCounters" => "%{[SensorProcessingCounters][0]}" } } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2018, 3:27pm UTC](https://discuss.elastic.co/t/logstash-error-parsing-xml-file/139720/5 "2018-08-10T15:27:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
