Hi team,
using the below logstash confg file xml filter
filter {
xml {
source => "message"
target => "xml_content"
}
split {
field => "xml_content[station]"
}
split {
field => "xml_content[station][name]"
}
mutate {
add_field => { "lastupdate" => "%{xml_content[lastupdate]}" }
add_field => { "name" => "%{xml_content[station][name][name]}" }
remove_field => ['xml_content', 'message', 'path']
}
}
getting invalid results check in kibana results
tags:multiline, _xmlparsefailure, _split_type_failure @timestamp:July 23rd 2018, 16:42:16.662 name:%{xml_content[station][name][name]} @version:1 lastupdate:%{xml_content[lastupdate]} _id:GmfXxmQBPb0XzgMOBBMj _type:doc _index:xmltest _score: -
can anyone help me on this thanks in advance