# Logstash XML xpath function like PHP $father-\>children()

**URL:** <https://discuss.elastic.co/t/logstash-xml-xpath-function-like-php-father-children/308719>\
**Category:** Logstash\
**Created:** [July 2, 2022, 12:13pm UTC](https://discuss.elastic.co/t/logstash-xml-xpath-function-like-php-father-children/308719 "2022-07-02T12:13:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Samuele\_Lolli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samuele_lolli/32/107848_2.png) [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Post date:** [July 2, 2022, 12:13pm UTC](https://discuss.elastic.co/t/logstash-xml-xpath-function-like-php-father-children/308719/1 "2022-07-02T12:13:59Z")

</div>

I'm searching if in logstash exist a xpath function like the one in PHP to get the child of a node without knowing the name.

Thanks to everyone

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 2, 2022, 4:47pm UTC](https://discuss.elastic.co/t/logstash-xml-xpath-function-like-php-father-children/308719/2 "2022-07-02T16:47:22Z")

</div>

"without knowing the name" -- the name of the parent or the name of the child? Anyways, if you start with

```
input { generator { count => 1 lines => ['<e1><e2><a /><b>foo</b><c>bar<d>baz</d></c></e2></e1>'] } }

```

and use an xml filter

```
    xml {
        source => "message"
        store_xml => false
        xpath => {
            "/*/*/*/node()" => "children"
        }
    }

```

then you will get

```
  "children" => [
    [0] "foo",
    [1] "bar",
    [2] "<d>baz</d>"
],

```

`"/*/*/*/text()"` will result in

```
  "children" => [
    [0] "foo",
    [1] "bar"
],

```

`"/*/*/*"` will result in

```
  "children" => [
    [0] "<a/>",
    [1] "<b>foo</b>",
    [2] "<c>bar<d>baz</d></c>"
],

```

It is unclear what you are asking for since you have not explained what the PHP children function does.

---

<div class="post-metadata">

**Author:** ![Samuele\_Lolli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samuele_lolli/32/107848_2.png) [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Post date:** [July 3, 2022, 7:22am UTC](https://discuss.elastic.co/t/logstash-xml-xpath-function-like-php-father-children/308719/3 "2022-07-03T07:22:00Z")

</div>

Thanks Badger!  
Yes i mean the name of the child.  
I think the one i need is the node().  
Thank you i try it later

---

<div class="post-metadata">

**Author:** ![Samuele\_Lolli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samuele_lolli/32/107848_2.png) [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Post date:** [July 3, 2022, 7:28am UTC](https://discuss.elastic.co/t/logstash-xml-xpath-function-like-php-father-children/308719/4 "2022-07-03T07:28:08Z")

</div>

Worked like i need it! Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2022, 7:29am UTC](https://discuss.elastic.co/t/logstash-xml-xpath-function-like-php-father-children/308719/5 "2022-07-31T07:29:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
