# No idea how to setup pipeline for the xml parsing

**URL:** <https://discuss.elastic.co/t/no-idea-how-to-setup-pipeline-for-the-xml-parsing/370243>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [November 8, 2024, 6:42pm UTC](https://discuss.elastic.co/t/no-idea-how-to-setup-pipeline-for-the-xml-parsing/370243 "2024-11-08T18:42:23Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![gpineda\_dev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gpineda_dev/32/137494_2.png) [@gpineda\_dev](https://discuss.elastic.co/u/gpineda_dev)\
**Post date:** [November 10, 2024, 12:19am UTC](https://discuss.elastic.co/t/no-idea-how-to-setup-pipeline-for-the-xml-parsing/370243/4 "2024-11-10T00:19:14Z")

</div>

The code you initialy posted would be the one for a logstash pipeline, not filebeat or even elasticsearch.

Usually the **data flow** is the following :

- filebeat -\> elasticsearch
- filebeat -\> logstash -\> elasticsearch
- logstash -\> elasticsearch

**Filebeat (beats) is a "standalone" binary** deployed on the host where you want to collect data while **logstash can indead collect logs but requires JVM** to run.

Once **collected, the events are sent to elasticsearch** and, if requested, **an ingest pipeline will be executed** on your event during ingestion resulting in a new document within your target index.

So in your case, since you mentioned filebeat, I assume you plan using filebeat to access the logs, then send it to logstash or directly elasticsearch.

Then to process XML log formated data with filebeat, you can indeed use [multiline](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html) to **extract as message your complete xml entry** and with the [decode\_xml processor](https://www.elastic.co/guide/en/beats/filebeat/current/decode-xml.html) from filebeat or [logstash xml filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-xml.html), **parse your "message"** entry to an actual xml.

```yaml
filebeat.inputs:
- type: filestream
  id: my-filestream-id
  paths:
    - /opt/path/to/my/xml.log
  parsers:
    - multiline:
         type: pattern
         pattern: '^<record>'
         negate: true
         match: after

# xml conversion can be within the same filebeat.yaml or handed over to logstash.
# if in the same :
processors:
  - decode_xml:
      field: message
      target_field: "record"
      overwrite_keys: true

# any output (here logstash is not necessary)

```

[Here is a similar thread about it](https://discuss.elastic.co/t/filebeat-process-multilne-xml/77761)

_PS: This is my first post on the platform, so not sure if details are sufficient._

---

_[View the full topic](https://discuss.elastic.co/t/no-idea-how-to-setup-pipeline-for-the-xml-parsing/370243)._
