Logstash XML parsing failure due to no namespace defined


I would like to store XMLs in elastic, so when I give "store_xml => true", I get a parsing exception because my whole XML is wrapped by a tag "<C:Message>" and the prefix "C" is not having any definition unfortunately (I know it is wrong implementation but the centralized logging framework is adding this parent tag, so would not be able to change). Now to overcome this, is there any solution such as add namespace or remove a particular prefix as such? I do not want to remove all the prefixes present in the document.

Sample XML:



Logstash Team,

Help or suggestions required here. Kindly do.


You could use mutate+gsub to remove those.


Thanks a lot, your solution worked for replacing the necessary contents. However facing another exception while parsing huge XMLs. Have opened a new topic for the same. Marking your answer as solution.



This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.