# Parse XML sub tags as a separate log

**URL:** <https://discuss.elastic.co/t/parse-xml-sub-tags-as-a-separate-log/329832>\
**Category:** Logstash\
**Created:** [April 12, 2023, 12:36pm UTC](https://discuss.elastic.co/t/parse-xml-sub-tags-as-a-separate-log/329832 "2023-04-12T12:36:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Disha\_Bodade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/disha_bodade/32/84522_2.png) [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Post date:** [April 12, 2023, 12:36pm UTC](https://discuss.elastic.co/t/parse-xml-sub-tags-as-a-separate-log/329832/1 "2023-04-12T12:36:56Z")

</div>

Hi Team,  
I have a XML formatted as below

```auto
<?xml version="1.0" encoding="UTF-8"?> 
<documents>
<Document><docID>101074476</docID><Title>End of Sale 1403 and 1416</Title><Author>clark13</Author></Document>
<Document><docID>101074474</docID><Title>End of Sale 1406 and 1417</Title><Author>clark14</Author></Document>
</document>

```

I need each `<Document>` as a separate log and then use xml filter on it.  
I have used multiline codec as below

```auto
codec => multiline {
                pattern => "<Document>"
                negate => "true"
                what => "previous"
                }

```

but its not considering last entry from xml file. To add all logs as event I am adding empty `<Document></Document>` at last.

I think there is some change needs in multiline codec. Not sure what I can add to consider all from XML.

Thanks,  
Disha

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 12, 2023, 3:43pm UTC](https://discuss.elastic.co/t/parse-xml-sub-tags-as-a-separate-log/329832/2 "2023-04-12T15:43:17Z")

</div>

You are not getting the last entry because the codec will not flush an event until the pattern matches. There is no line that matches the pattern after the last line that does so (obviously), so the last line is never flushed. You could set [`auto_flush_interval`](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html#plugins-codecs-multiline-auto_flush_interval).

Personally I would consume the entire document using a multiline codec, then parse the XML to get an array of Document elements and use a split filter to separate those into one per event.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2023, 3:43pm UTC](https://discuss.elastic.co/t/parse-xml-sub-tags-as-a-separate-log/329832/3 "2023-05-10T15:43:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
