# Logstash XML parsing failure due to no namespace defined

**URL:** <https://discuss.elastic.co/t/logstash-xml-parsing-failure-due-to-no-namespace-defined/230890>\
**Category:** Logstash\
**Created:** [May 3, 2020, 6:10pm UTC](https://discuss.elastic.co/t/logstash-xml-parsing-failure-due-to-no-namespace-defined/230890 "2020-05-03T18:10:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saravana\_Maadavan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saravana_maadavan/32/60232_2.png) [@Saravana\_Maadavan](https://discuss.elastic.co/u/Saravana_Maadavan)\
**Post date:** [May 3, 2020, 6:10pm UTC](https://discuss.elastic.co/t/logstash-xml-parsing-failure-due-to-no-namespace-defined/230890/1 "2020-05-03T18:10:50Z")

</div>

Hello,

I would like to store XMLs in elastic, so when I give "store\_xml =\> true", I get a parsing exception because my whole XML is wrapped by a tag "\<C:Message\>" and the prefix "C" is not having any definition unfortunately (I know it is wrong implementation but the centralized logging framework is adding this parent tag, so would not be able to change). Now to overcome this, is there any solution such as add namespace or remove a particular prefix as such? I do not want to remove all the prefixes present in the document.

Sample XML:

> \<C:Message\>  
> \<Date\>03-05-2020\</Date\>  
> \<Time\>11:00:34\</Time\>  
> \<SOAP-ENV:Body\>  
> \<Customer\>2432532\</Customer\>  
> \</SOAP-ENV:Body\>  
> \</C:Message\>

Cheers,  
Maadavan

---

<div class="post-metadata">

**Author:** ![Saravana\_Maadavan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saravana_maadavan/32/60232_2.png) [@Saravana\_Maadavan](https://discuss.elastic.co/u/Saravana_Maadavan)\
**Post date:** [May 5, 2020, 5:27am UTC](https://discuss.elastic.co/t/logstash-xml-parsing-failure-due-to-no-namespace-defined/230890/2 "2020-05-05T05:27:48Z")

</div>

Logstash Team,

Help or suggestions required here. Kindly do.

Cheers,  
Maadavan

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 5, 2020, 3:29pm UTC](https://discuss.elastic.co/t/logstash-xml-parsing-failure-due-to-no-namespace-defined/230890/3 "2020-05-05T15:29:21Z")

</div>

You could use mutate+gsub to remove those.

---

<div class="post-metadata">

**Author:** ![Saravana\_Maadavan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saravana_maadavan/32/60232_2.png) [@Saravana\_Maadavan](https://discuss.elastic.co/u/Saravana_Maadavan)\
**Post date:** [May 7, 2020, 8:51pm UTC](https://discuss.elastic.co/t/logstash-xml-parsing-failure-due-to-no-namespace-defined/230890/4 "2020-05-07T20:51:31Z")

</div>

@Badger,

Thanks a lot, your solution worked for replacing the necessary contents. However facing another exception while parsing huge XMLs. Have opened a new topic for the same. Marking your answer as solution.

`https://discuss.elastic.co/t/logstash-throws-runtime-exception-while-parsing-huge-xml/231621`

Cheers,  
Maadavan

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2020, 8:51pm UTC](https://discuss.elastic.co/t/logstash-xml-parsing-failure-due-to-no-namespace-defined/230890/5 "2020-06-04T20:51:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
