# Logstash multiline codec with xml filter

**URL:** <https://discuss.elastic.co/t/logstash-multiline-codec-with-xml-filter/252593>\
**Category:** Logstash\
**Created:** [October 19, 2020, 6:34pm UTC](https://discuss.elastic.co/t/logstash-multiline-codec-with-xml-filter/252593 "2020-10-19T18:34:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arvind\_Ks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arvind_ks/32/77463_2.png) [@Arvind\_Ks](https://discuss.elastic.co/u/Arvind_Ks)\
**Post date:** [October 19, 2020, 6:34pm UTC](https://discuss.elastic.co/t/logstash-multiline-codec-with-xml-filter/252593/1 "2020-10-19T18:34:05Z")

</div>

Hello Everyone i have a input xml file, that i am using to send to elasticsearch.  
i want all fields within and . However i am getting below error. pls suggest.

Input file

2020-09-30 11:59:54,755 (Test worker) JobScheduler INFO: Start scheduling jobs: 2  
2020-09-30 11:59:54,755 (Test worker) JobScheduler INFO: Job 1 is not qualified for cloud  
2020-09-30 11:59:54,755 (Test worker) JobScheduler INFO: Scheduling results: 1 out of 2 is assigned  
  
  
0.02  
2020-09-30T18:59:54  
0.02  
  
  
  
  
0.005  
com.amobee.scheduler.SchedulerTest  
testJobComparator  
false  
0

This is the config file im using

[root@app861.sjc2.turn.com ~]# cat /etc/logstash/conf.d/jenkins-ciatl1-test.conf  
input {  
file {  
#path =\> "/home/ashivaramakrishnan/junitResult-test.xml"  
path =\> "/home/ashivaramakrishnan/junitResult.xml"  
start\_position =\> "beginning"  
codec =\> multiline {

# We assume every line starting with starts with 8 spaces, so lines with \> 8 space, or first non-whitespace is \</.., or doesn't have xml tag (to

# catch some wrapped strings in stack trace), are attached to previous line

#pattern =\> "(^\s{9,}\<\w+\>)|(^\s\*\</)|(^\s\*[\w])"  
#pattern =\> "^(\s+)(^\s\*\</)|(^\s\*[\w])"  
#pattern =\> "(^\s\*\<case+._)"  
pattern =\> "^\<?case ._\>"  
negate =\> "true"  
what =\> "previous"  
auto\_flush\_interval =\> 5  
}  
}  
}

filter {  
xml {  
store\_xml =\> false  
source =\> "message"  
target =\> "xml\_content"  
#remove\_namespaces =\> true  
xpath =\>  
[  
"/case/testName/text()", "testcaseName",  
"/case/className/text()", "className",  
"/case/errorStackTrace/text()", "errorStackTrace"  
]  
remove\_field =\> "message"  
}

#if ![errorStackTrace] or ![className] or ![testcaseName] {

# drop { }

#}

if "\_grokparsefailure" in [tags] {  
drop {}  
}

}

output {  
stdout {  
codec =\> rubydebug {  
}  
}

I want output to be something like below. But getting max lines reached error.

"testcaseName" =\> [  
[0] "testJobComparator"  
],  
"tags" =\> [  
[0] "multiline",  
[1] "multiline\_codec\_max\_lines\_reached"  
],  
"@version" =\> "1",  
"host" =\> "[app861.sjc2.turn.com](http://app861.sjc2.turn.com)",  
"className" =\> [  
[0] "com.amobee.scheduler.SchedulerTest"  
],  
"path" =\> "/home/ashivaramakrishnan/junitResult.xml"

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 19, 2020, 7:00pm UTC](https://discuss.elastic.co/t/logstash-multiline-codec-with-xml-filter/252593/2 "2020-10-19T19:00:08Z")

</div>

Please format your post to make it readable. Select your log file entries and click on \</\> in the toolbar above the edit pane. Then do the same for the configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2020, 7:00pm UTC](https://discuss.elastic.co/t/logstash-multiline-codec-with-xml-filter/252593/3 "2020-11-16T19:00:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
