Thanks a lot @magnusbaeck your analysis is correct. It worked, logstash able to process the xml by adding those two line max_lines and max_bytes. Below are my current config file, i don't know if my max_lines parameter are overkill or not
By the way another question not related to the parsing, why is my data count is showing only 1 while the data contain more than that, for example the risk_score field for "0" value have 179 data, when i try to visualize it only show 1 count.
Not knowing what the data looks like I don't have anything useful to say regarding your last question. Re the previous question of why you're only seeing 179 counts of zero it might be because the quick analysis you get when you click on a field it's based on the 500 most recent events.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.