# Logstash parsing is not giving exact value

**URL:** <https://discuss.elastic.co/t/logstash-parsing-is-not-giving-exact-value/141411>\
**Category:** Logstash\
**Created:** [July 24, 2018, 2:51pm UTC](https://discuss.elastic.co/t/logstash-parsing-is-not-giving-exact-value/141411 "2018-07-24T14:51:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![satendr](https://avatars.discourse-cdn.com/v4/letter/s/c89c15/32.png) [@satendr](https://discuss.elastic.co/u/satendr)\
**Post date:** [July 24, 2018, 2:51pm UTC](https://discuss.elastic.co/t/logstash-parsing-is-not-giving-exact-value/141411/1 "2018-07-24T14:51:07Z")

</div>

Hi , I am trying to parse a XML result file

input {  
file {  
path =\> "C:/win10Automation/mytest/test\_out.xml"  
start\_position =\> "beginning"  
type =\> "xml"  
sincedb\_path =\> "/dev/null"  
codec =\> multiline {  
pattern =\> "^\<status\b"  
negate =\> true  
what =\> "previous"  
max\_lines =\> 300000  
auto\_flush\_interval =\> 10  
}  
}

#beats {  
# port =\> "5044"  
#}  
}

filter {  
xml {  
remove\_namespaces =\> true  
source =\> "message"  
store\_xml =\> false

xpath =\>  
[  
"suite/test/kw/kw/kw/kw/status", "matafmethod",  
"suite/test/kw/kw/kw/kw/status/@status", "matafteststatus"  
]  
}

```
split {
field => "matafteststatus"
remove_field => "message" # the whole message isn't particularly applicable to individual events after the split

```

}  
mutate {  
add\_field =\> ["myteststatus" ,"%{matafteststatus}"]

```
			}

```

}

output {  
elasticsearch {  
codec =\> json  
hosts =\> "localhost:9200"  
index =\> "test56"  
}

stdout {  
codec =\> rubydebug  
}

but instead of getting  
status="PASS"  
i am getting result  
  
also \_split\_type\_failure error ,

```
<suite source="/Users/SourceCode/Tests/TestScripts/TestSuite4/mytc_TC_002.txt" id="s1-s1-s2" name="mytc TC 002">
<test id="s1-s1-s2-t1" name="mytc_TC_002">
<kw name="Run Keyword If" library="BuiltIn">
<kw name="IOS Script">
<kw name="Launch IOSApplication" library="CommonFunc">
<kw name="Run Keyword And Return Status" library="BuiltIn">
<status status="PASS" endtime="20180710 17:52:49.411" starttime="20180710 17:52:30.275"></status>
<status status="PASS" endtime="20180710 17:52:49.412" starttime="20180710 17:52:30.275"></status>
</kw>
</kw>
</kw>
</kw>
</test>
</suite>

```

here is sample XML file  
please help to resolve

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 24, 2018, 2:59pm UTC](https://discuss.elastic.co/t/logstash-parsing-is-not-giving-exact-value/141411/2 "2018-07-24T14:59:40Z")

</div>

Your post is unreadable as-is. Please select the config and the xml (separately) and click on \</\> in the toolbar above the composition window. You should see a change in the preview window to the right of the composition window.

Also, do not delete message (or other fields that you parse) until you are sure they are being parsed correctly. Also the output of this might help

```
output { stdout { codec => rubydebug } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2018, 2:59pm UTC](https://discuss.elastic.co/t/logstash-parsing-is-not-giving-exact-value/141411/3 "2018-08-21T14:59:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
