Hi,
I am ingesting an XML file that looks like this:
<Events>
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"> - about 630,000 of these events
... stuff
</Event>
</Events>
The input section of my config file looks like this:
input {
file {
path => "c:/traces/pcbd/20200327/wininettrace.xml"
start_position => "beginning"
sincedb_path => "NUL"
type => "wininet"
codec => multiline {
pattern => "<Event "
negate => true
what => "previous"
}
}
}
The ingestion runs to completion, but right at the start I get this error:
Error parsing xml with XmlSimple {:source=>"message", :value=>"<Events>\r", :exception=>#<REXML::ParseException: No close tag for /Events
What do I need to do to get the multiline codec to ignore the <Events>
and </Events>
tags?