# Logstash XML file not parsing

**URL:** <https://discuss.elastic.co/t/logstash-xml-file-not-parsing/352048>\
**Category:** Logstash\
**Created:** [January 30, 2024, 3:27am UTC](https://discuss.elastic.co/t/logstash-xml-file-not-parsing/352048 "2024-01-30T03:27:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shawn\_Lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shawn_lim/32/122022_2.png) [@Shawn\_Lim](https://discuss.elastic.co/u/Shawn_Lim)\
**Post date:** [January 30, 2024, 3:27am UTC](https://discuss.elastic.co/t/logstash-xml-file-not-parsing/352048/1 "2024-01-30T03:27:01Z")

</div>

Hi guys,

I'm very new to Elasticsearch stack, need some help over here...  
Currently I'm trying to parse XML file, output to Elasticsearch and use it on Grafana for visualization. Now I facing a problem is my XML files are not parsing, not sure is my Logstash input pattern or/and the filter misconfigured.

Here are the resources:  
XML format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37d6772fa96ffa05af0433fc18219f780764b2b5.png)

```auto
<log>
  <entry>
    <log_time>20230926-00:00:00</log_time>
    <description><![CDATA[Connection established]]></description>
    <service>FTP</service>
    <sessionid>16692722</sessionid>
    <type>0</type> <severity>0</severity>
    <lstnconnaddr>x.x.x.156:21</lstnconnaddr>
    <cliconnaddr>x.x.x.132:52948</cliconnaddr>
    <cmd>start</cmd>
    <sguid>C89C2B68-A602-4D43-6094-1CA63B6268A4</sguid>
  </entry>
  <entry>
    <log_time>20230926-00:00:01</log_time>
    <description><![CDATA[Connection established]]></description>
    <service>FTP</service>
    <sessionid>08919335</sessionid>
    <type>0</type> <severity>0</severity>
    <lstnconnaddr>x.x.x.156:21</lstnconnaddr>
    <cliconnaddr>x.x.x.136:58003</cliconnaddr>
    <cmd>start</cmd>
    <sguid>C89C2B68-A602-4D43-6094-1CA63B6268A4</sguid>
  </entry>
</log>

Logstash config file:
input {
  file {
    path => "/tmp/*.xml"
    start_position => "beginning"
    sincedb_path => "/dev/null"
    sincedb_clean_after => 0.1
    sincedb_write_interval => 30
    type => "xml"
    codec => multiline {
      pattern => "^<log>"
      negate => "true"
      what => "previous"
    }
    file_sort_by => "last_modified"
  }
}

filter {
  xml {
    source => "message"
    target => "xmlLog"
    store_xml => false
    xpath => [
      "/entry/log_time/text()", "log_time",
      "/log/entry/description/text()", "description",
      "/log/entry/service/text()", "service",
      "/log/entry/sessionid/text()", "sessionid",
      "/log/entry/type/text()", "type",
      "/log/entry/severity/text()", "severity",
      "/log/entry/cmd/text()", "cmd",
      "/log/entry/sguid/text()", "sguid"
    ]
  }

  mutate {
    gsub => ["message", "\r\n", ""]
  }

  mutate {
    remove_field => ["@version","tags","_score", "_type", "type", "event", "<?xml version=\"1.0\" encoding=\"utf-8\" ?>\r", "\r\n", "host"]
  }
}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
    user => "elastic"
  }
  stdout {
    codec => rubydebug
  }
}
```

---

<div class="post-metadata">

**Author:** ![Shawn\_Lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shawn_lim/32/122022_2.png) [@Shawn\_Lim](https://discuss.elastic.co/u/Shawn_Lim)\
**Post date:** [January 30, 2024, 7:15am UTC](https://discuss.elastic.co/t/logstash-xml-file-not-parsing/352048/2 "2024-01-30T07:15:43Z")

</div>

@Badger I saw you given a lot of advise of previous related issue, can you help me too?

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [January 30, 2024, 9:31am UTC](https://discuss.elastic.co/t/logstash-xml-file-not-parsing/352048/3 "2024-01-30T09:31:03Z")

</div>

Hi,

the root of the XML document is `<log>`, so you should start your XPath expressions with `/log/entry/`.

```auto
filter {
  xml {
    source => "message"
    target => "xmlLog"
    store_xml => false
    xpath => [
      "/log/entry/log_time/text()", "log_time",
      "/log/entry/description/text()", "description",
      "/log/entry/service/text()", "service",
      "/log/entry/sessionid/text()", "sessionid",
      "/log/entry/type/text()", "type",
      "/log/entry/severity/text()", "severity",
      "/log/entry/cmd/text()", "cmd",
      "/log/entry/sguid/text()", "sguid"
    ]
  }

```

Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2024, 9:31am UTC](https://discuss.elastic.co/t/logstash-xml-file-not-parsing/352048/4 "2024-02-27T09:31:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
