# Need to parse xml by logstash and create an event only if a field value is non zero

**URL:** <https://discuss.elastic.co/t/need-to-parse-xml-by-logstash-and-create-an-event-only-if-a-field-value-is-non-zero/303306>\
**Category:** Logstash\
**Created:** [April 26, 2022, 4:05pm UTC](https://discuss.elastic.co/t/need-to-parse-xml-by-logstash-and-create-an-event-only-if-a-field-value-is-non-zero/303306 "2022-04-26T16:05:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rohit\_Goel1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohit_goel1/32/46637_2.png) [@Rohit\_Goel1](https://discuss.elastic.co/u/Rohit_Goel1)\
**Post date:** [April 26, 2022, 4:05pm UTC](https://discuss.elastic.co/t/need-to-parse-xml-by-logstash-and-create-an-event-only-if-a-field-value-is-non-zero/303306/1 "2022-04-26T16:05:02Z")

</div>

Hi Team ,

I have few Jenkins build xml files generated when jenkins jobs are triggered. I have to read few tags from the xml and create new fields from them by parsing it through logstash.

The xml has one tag `<duration>` which has a value 0 in the start but it gets updated to actual value once jenkins job is completed. My logstash is reading the xml and sending value 0 in event but not reading the updated tag once xml is updated .

is there a way my xml is only read by logstash if my xml tag value in `<duration>` is non zero. and if zero to skip the parsing of xml.

below is my logstash conf:

```auto
logstash.conf: |
    input {
      file {
        path => "/var/jenkins_home/jobs/**/branches/*/builds/*/build.xml"
        start_position => "beginning"
        sincedb_path => "/dev/null"
        type => "xml"
        codec => multiline {
           pattern => '^[A-Z]{1}[a-z]{2} {1,2}[0-9]{1,2},[0-9]{4} {1,2}[0-9]{1,2}:[0-9]{2}:[0-9]{2}'
           negate => true
           what => previous
           max_lines => 10000000000
           auto_flush_interval => 60
        }
      }
    }
    filter {
      xml {
        source => "message"
        store_xml => false
        xpath => [
            "/flow-build/startTime/text()", "startTime",
            "/flow-build/duration/text()", "duration",
            "/flow-build/execution/result/text()", "result"
        ]
        remove_field => ["message"]
      }
    }
   output {
      elasticsearch { hosts => ["https://elastic:443/elasticsearch"] index => "elktest-%{+YYYY.MM.dd}" }
      stdout { codec => rubydebug }
    }

```

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [April 28, 2022, 1:03pm UTC](https://discuss.elastic.co/t/need-to-parse-xml-by-logstash-and-create-an-event-only-if-a-field-value-is-non-zero/303306/2 "2022-04-28T13:03:58Z")

</div>

Hi,

First, to make logstash read the file when he is edited, you need to set the sincedb\_path properly. I let you read the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#_tracking_of_current_position_in_watched_files).

Next, to not send the values to Elasticsearch if the field duration is equals to zero, i recommend you to use one conditionnal. You have an example [here](https://www.elastic.co/guide/en/logstash/current/plugins-filters-drop.html) and the documentation of the conditionnal is [here](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html).

Cad.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2022, 1:04pm UTC](https://discuss.elastic.co/t/need-to-parse-xml-by-logstash-and-create-an-event-only-if-a-field-value-is-non-zero/303306/3 "2022-05-26T13:04:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
