# Logstash - XML Filter not working properly

**URL:** <https://discuss.elastic.co/t/logstash-xml-filter-not-working-properly/176758>\
**Category:** Logstash\
**Created:** [April 14, 2019, 3:16am UTC](https://discuss.elastic.co/t/logstash-xml-filter-not-working-properly/176758 "2019-04-14T03:16:53Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 14, 2019, 8:44pm UTC](https://discuss.elastic.co/t/logstash-xml-filter-not-working-properly/176758/10 "2019-04-14T20:44:32Z")

</div>

With that XML in a generator input and that filter, I get 4 messages. It might be time to take a closer look at how your multiline pattern is performing.

Getting the first line of XML (the \<?xml...) as a separate line, which of course will not parse, is expected. You will also be missing the last entry in the file, since there is no line matching " \<CxXMLResults" to flush the last event.

Using auto\_flush\_interval on the file input might help.

If you just want to consume the entire file in a single event (which you can then split) I normally use a pattern that never matches.

```
codec => multiline { pattern => "^Spalanzani" what => "previous" negate => true auto_flush_interval => 1 } } }
```

---

_[View the full topic](https://discuss.elastic.co/t/logstash-xml-filter-not-working-properly/176758)._
