# Parse XML log with xml filter and grok fiter

**URL:** <https://discuss.elastic.co/t/parse-xml-log-with-xml-filter-and-grok-fiter/286712>\
**Category:** Logstash\
**Created:** [October 14, 2021, 10:58am UTC](https://discuss.elastic.co/t/parse-xml-log-with-xml-filter-and-grok-fiter/286712 "2021-10-14T10:58:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Catalina\_Boteanu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/catalina_boteanu/32/78091_2.png) [@Catalina\_Boteanu](https://discuss.elastic.co/u/Catalina_Boteanu)\
**Post date:** [October 14, 2021, 10:58am UTC](https://discuss.elastic.co/t/parse-xml-log-with-xml-filter-and-grok-fiter/286712/1 "2021-10-14T10:58:56Z")

</div>

Hello. I am currently trying to apply some filters to different logs in Logstash. I have a log that has a string in the beginning and then it is in xml format. I was able to take out the xml from the log with a regex. Now I want to send this xml in a xml predefined filter to transform it in JSON.  
How can I do that? This is the filters I have written so far:

```auto
filter {
    grok{
        match => {
            "message" => ["(?<xml><\?xml[\s\S]*?<\SAuditMessage>)"]
        }
    }

    xml {
      ["xml"] => "FinalXml" 
      target => "doc"
      force_content => "true"
    }
}

```

The logs look like this:

```auto
Sep 7 15:06:01 ip-xxx-xxx-xxx-xxx<?xml version="1.0" encoding="UTF-8"?>
<AuditMessage>
    <Here we have more fields>
</AuditMessage>

```

Currently, Logstash is crashig with this configuration:))

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 15, 2021, 5:34pm UTC](https://discuss.elastic.co/t/parse-xml-log-with-xml-filter-and-grok-fiter/286712/2 "2021-10-15T17:34:46Z")

</div>

You could try

```
xml {
    source => "message"
    target => "doc"
    force_content => true
}

```

If you are using store\_xml =\> true (the default) then the xml filter will tolerate junk surrounding the xml, so you do not need the grok. This is not true if you use xpath.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2021, 5:35pm UTC](https://discuss.elastic.co/t/parse-xml-log-with-xml-filter-and-grok-fiter/286712/3 "2021-11-12T17:35:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
