# Logstash: Input File Plugin Showing Zero Events

**URL:** <https://discuss.elastic.co/t/logstash-input-file-plugin-showing-zero-events/336097>\
**Category:** Logstash\
**Created:** [June 15, 2023, 12:59pm UTC](https://discuss.elastic.co/t/logstash-input-file-plugin-showing-zero-events/336097 "2023-06-15T12:59:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksaimohan2k](https://avatars.discourse-cdn.com/v4/letter/k/f4b2a3/32.png) [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Post date:** [June 15, 2023, 12:59pm UTC](https://discuss.elastic.co/t/logstash-input-file-plugin-showing-zero-events/336097/1 "2023-06-15T12:59:36Z")

</div>

Hello, I am new to elastic. I am trying to parse XML logs using Logstash. As a result, I am using an input file plugin, and for the filtering process, I am using an XML plugin.  
Pipeline is running successfully, but showing the number of events as 0 means it's not taking input or processing any data. Below is the code within  
test.conf file for the reference.

```auto
input
{
  file
  {
    path => "C:\ELKStack\samplelog.xml"
    start_position => "beginning"
    sincedb_path => "C:/ELKStack/logstash-8.8.1-windows-x86_64/logstash-8.8.1/data/sincedb"
    codec => multiline 
    {
      pattern => "<entry>"
      negate => true
      what => "previous"
    }
  }
}
filter
{
  xml
  {
    source => "message"
    store_xml => true
    target => "parsed_log"
    force_array => false 
    xpath=> [
      "/log/entry/timestamp/text()","timestamp", 
      "/log/entry/message/text()","message"
      ]
  }
}
output
{
  stdout{}
}

```

I also checked and modified the file permissions within the permissions for users, system, and administrators, giving them full control of the file.  
I am also pasting, sample log below for reference.

```auto
<log>
  <entry>
    <timestamp>2023-06-12 10:35:21</timestamp>
    <message>Application started</message>
  </entry>
  <entry>
    <timestamp>2023-06-12 10:38:12</timestamp>
    <message>User logged in</message>
  </entry>
  <entry>
    <timestamp>2023-06-12 10:42:05</timestamp>
    <message>Error: Invalid input detected</message>
  </entry>
  <entry>
    <timestamp>2023-06-12 10:46:32</timestamp>
    <message>Database connection established</message>
  </entry>
  <entry>
    <timestamp>2023-06-12 10:48:55</timestamp>
    <message>Record inserted successfully</message>
  </entry>
</log>

```

Kindly let me know if there are any modifications.  
Thanks in Advance

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 15, 2023, 4:08pm UTC](https://discuss.elastic.co/t/logstash-input-file-plugin-showing-zero-events/336097/2 "2023-06-15T16:08:12Z")

</div>

> [@ksaimohan2k](#):
>
> `path => "C:\ELKStack\samplelog.xml"`

Do not use backslash in the path option of a file input. It is treated as an escape, so logstash is waiting for "C:ELKStacksamplelog.xml" to be created. Use forward slash (or \\).

---

<div class="post-metadata">

**Author:** ![ksaimohan2k](https://avatars.discourse-cdn.com/v4/letter/k/f4b2a3/32.png) [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Post date:** [June 16, 2023, 5:21am UTC](https://discuss.elastic.co/t/logstash-input-file-plugin-showing-zero-events/336097/3 "2023-06-16T05:21:34Z")

</div>

Thanks @Badger, Resolved it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2023, 5:22am UTC](https://discuss.elastic.co/t/logstash-input-file-plugin-showing-zero-events/336097/4 "2023-07-14T05:22:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
