# Parse Single Line XML In Logstash

**URL:** <https://discuss.elastic.co/t/parse-single-line-xml-in-logstash/199884>\
**Category:** Logstash\
**Created:** [September 17, 2019, 9:27pm UTC](https://discuss.elastic.co/t/parse-single-line-xml-in-logstash/199884 "2019-09-17T21:27:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![babaturk](https://avatars.discourse-cdn.com/v4/letter/b/49beb7/32.png) [@babaturk](https://discuss.elastic.co/u/babaturk)\
**Post date:** [September 17, 2019, 9:27pm UTC](https://discuss.elastic.co/t/parse-single-line-xml-in-logstash/199884/1 "2019-09-17T21:27:07Z")

</div>

I am trying to output from Logstash to Elasticsearch the "result" (pass) in my xml file that consists of this single line:

```
 <test_results><test_result result="pass" title="Name_Of_Test"></test_result></test_results>

```

Here is my config file:

input{  
file{  
path =\> "C:\Test.xml"  
start\_position =\> "beginning"  
}  
}

filter {  
xml {  
source =\> "message"  
store\_xml =\> false  
target =\> "xml\_content"  
xpath =\>  
[  
"/test\_results/test\_result[@result]", "result"  
]  
}  
}  
output {  
stdout { codec =\> rubydebug }  
}

When Ioad logstash with the config file, I get the following:

C:\logstash-6.7.1\bin\>logstash -f logstash2.conf  
Sending Logstash logs to C:/logstash-6.7.1/logs which is now configured via log4j2.properties  
[2019-09-17T17:21:29,303][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2019-09-17T17:21:29,318][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.7.1"}  
[2019-09-17T17:21:34,498][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>12, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[2019-09-17T17:21:36,426][INFO][logstash.inputs.file] No sincedb\_path set, generating one based on the "path" setting {:sincedb\_path=\>"C:/logstash-6.7.1/data/plugins/inputs/file/.sincedb\_903218998ef9435ea312b7206f56cac9", :path=\>["C:\Test.xml"]}  
[2019-09-17T17:21:36,462][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x2535e1df run\>"}  
[2019-09-17T17:21:36,496][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2019-09-17T17:21:36,500][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
[2019-09-17T17:21:36,766][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

I am wondering if the issue could be that my input plugin is not generating events or something is wrong with my installation of the xml filter plugin.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 17, 2019, 11:01pm UTC](https://discuss.elastic.co/t/parse-single-line-xml-in-logstash/199884/2 "2019-09-17T23:01:17Z")

</div>

> [@babaturk](#):
>
> path =\> "C:\Test.xml"

Do not use backslash in the path option of a file input. Use forward slash.

---

<div class="post-metadata">

**Author:** ![babaturk](https://avatars.discourse-cdn.com/v4/letter/b/49beb7/32.png) [@babaturk](https://discuss.elastic.co/u/babaturk)\
**Post date:** [September 18, 2019, 12:58pm UTC](https://discuss.elastic.co/t/parse-single-line-xml-in-logstash/199884/3 "2019-09-18T12:58:41Z")

</div>

Thank you, I changed it to a forward slash instead but still got the same output after running again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 16, 2019, 12:58pm UTC](https://discuss.elastic.co/t/parse-single-line-xml-in-logstash/199884/4 "2019-10-16T12:58:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
