# Logstash parsing XML failing on second and subsequent records

**URL:** <https://discuss.elastic.co/t/logstash-parsing-xml-failing-on-second-and-subsequent-records/308905>\
**Category:** Logstash\
**Created:** [July 5, 2022, 12:20pm UTC](https://discuss.elastic.co/t/logstash-parsing-xml-failing-on-second-and-subsequent-records/308905 "2022-07-05T12:20:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gerrard](https://avatars.discourse-cdn.com/v4/letter/g/898d66/32.png) [@Gerrard](https://discuss.elastic.co/u/Gerrard)\
**Post date:** [July 5, 2022, 12:20pm UTC](https://discuss.elastic.co/t/logstash-parsing-xml-failing-on-second-and-subsequent-records/308905/1 "2022-07-05T12:20:08Z")

</div>

Hi, I'm struggling to understand why logstash is unable to process any records beyond the first in my XML log file. The first record is parsed fine, but then any following ones get the "\_xmlparsefailure" tag.

My log file is in this format:

```auto
<?xml version="1.0" encoding="utf-16"?><Log><DateTime>2022-07-04T10:40:49.2352382+01:00</DateTime><Level>Information</Level><ServiceGUID>6d62412d-7a7e-4087-9e0c-38f665474839</ServiceGUID></Log>&#xD;
<?xml version="1.0" encoding="utf-16"?><Log><DateTime>2022-07-04T10:40:49.2382446+01:00</DateTime><Level>Information</Level><ServiceGUID>6d62412d-7a7e-4087-9e0c-38f665474839</ServiceGUID></Log>&#xD;
<?xml version="1.0" encoding="utf-16"?><Log><DateTime>2022-07-04T10:40:59.3376527+01:00</DateTime><Level>Error</Level><ServiceGUID>72d0d523-662c-4545-899f-571f3969a441</ServiceGUID></Log>&#xD;

```

and this is my logstash config file:

```auto
input {
	file {
		path => "C:/temp/Log_Files/*.xml"
		start_position => "beginning"
		sincedb_path => "NUL"
		codec => plain {
			charset => "UTF-16"
		}
	}
}
filter {
	xml {
		source => "message"
		target => "parsed"
	}
}
output {
	stdout {
		codec => rubydebug
	}
}

```

I've tried the same log file without the text at the end of each line and that doesn't seem to make any difference (not sure what that random text is anyway.)

The output from the first record looks like this:

```auto
{
        "parsed" => {
              "Level" => [
            [0] "Information"
        ],
           "DateTime" => [
            [0] "2022-07-04T10:40:49.2352382+01:00"
        ],
        "ServiceGUID" => [
            [0] "6d62412d-7a7e-4087-9e0c-38f665474839"
        ]
    },
          "host" => {
        "name" => "HOSTNAME"
    },
    "@timestamp" => 2022-07-05T12:13:07.202461500Z,
      "@version" => "1",
           "log" => {
        "file" => {
            "path" => "C:/temp/Log_Files/2022-07-04T00.00#2022-07-05T00.00.xml"
        }
    },
       "message" => "<?xml version=\"1.0\" encoding=\"utf-16\"?><Log><DateTime>2
022-07-04T10:40:49.2352382+01:00</DateTime><Level>Information</Level><ServiceGUI
D>6d62412d-7a7e-4087-9e0c-38f665474839</ServiceGUID></Log>&#xD;\r",
         "event" => {
        "original" => "<?xml version=\"1.0\" encoding=\"utf-16\"?><Log><DateTime
>2022-07-04T10:40:49.2352382+01:00</DateTime><Level>Information</Level><ServiceG
UID>6d62412d-7a7e-4087-9e0c-38f665474839</ServiceGUID></Log>&#xD;\r"
    }
}

```

but the output from the second and subsequent records looks like this:

```auto
{
          "host" => {
        "name" => "HOSTNAME"
    },
    "@timestamp" => 2022-07-05T12:13:07.210459300Z,
          "tags" => [
        [0] "_xmlparsefailure"
    ],
      "@version" => "1",
           "log" => {
        "file" => {
            "path" => "C:/temp/Log_Files/2022-07-04T00.00#2022-07-05T00.00.xml"
        }
    },
       "message" => "???????????????????????????????????????????????????????????
????????????????????????????????????????????????????????????????????????????????
??????????????????????????????????????????????????????",
         "event" => {
        "original" => "?????????????????????????????????????????????????????????
????????????????????????????????????????????????????????????????????????????????
????????????????????????????????????????????????????????"
    }
}

```

Anyone able to shed any light on what is missing or wrong?  
Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 5, 2022, 2:36pm UTC](https://discuss.elastic.co/t/logstash-parsing-xml-failing-on-second-and-subsequent-records/308905/2 "2022-07-05T14:36:30Z")

</div>

> [@Gerrard](#):
>
> I'm struggling to understand why logstash is unable to process any records beyond the first in my XML log file.

I suspect you are hitting [this](https://discuss.elastic.co/t/why-stdout-output-shows-message/214079/11) issue. The file input reads lines, and splitting the data into lines happens before the codec (and encoding) is applied, so it cannot properly process 16 bit characters.

---

<div class="post-metadata">

**Author:** ![Gerrard](https://avatars.discourse-cdn.com/v4/letter/g/898d66/32.png) [@Gerrard](https://discuss.elastic.co/u/Gerrard)\
**Post date:** [July 5, 2022, 2:54pm UTC](https://discuss.elastic.co/t/logstash-parsing-xml-failing-on-second-and-subsequent-records/308905/3 "2022-07-05T14:54:55Z")

</div>

Thanks Badger. I'll go back to our developers and see if we can get a different log output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2022, 2:55pm UTC](https://discuss.elastic.co/t/logstash-parsing-xml-failing-on-second-and-subsequent-records/308905/4 "2022-08-02T14:55:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
