# Regarding the XML file issue

**URL:** <https://discuss.elastic.co/t/regarding-the-xml-file-issue/185392>\
**Category:** Logstash\
**Created:** [June 12, 2019, 10:43am UTC](https://discuss.elastic.co/t/regarding-the-xml-file-issue/185392 "2019-06-12T10:43:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dilipchiru](https://avatars.discourse-cdn.com/v4/letter/d/7ea924/32.png) [@dilipchiru](https://discuss.elastic.co/u/dilipchiru)\
**Post date:** [June 12, 2019, 10:43am UTC](https://discuss.elastic.co/t/regarding-the-xml-file-issue/185392/1 "2019-06-12T10:43:18Z")

</div>

Hi ,

I have added the XML file configuration on the in the logstash where i sent the data to logstash and i can see the data is sent in the console and index is created in kibana but the data is not loaded in kibana and there are many XML start tag and end tags in one file and i have attached the screenshot

Note: basically i need all the data to be displayed in the kibana so only i am not writing anything in the filter section

below is my logstash.conf  
input {  
file {  
path =\> "/apps/VIL\_CDR/3rdJune/WBMTAS00119060301000003668.txt"  
sincedb\_path =\> "/dev/null"  
start\_position =\> "beginning"  
codec =\> multiline {  
pattern =\> "\<Report |"  
auto\_flush\_interval =\> 1  
negate =\> "true"  
what =\> "previous"  
max\_lines =\> 1000000000

```
}
  tags => "cdrlogs"
  type => "cdrlogs"

```

}  
}

filter {  
##interpret the message as XML  
if [type] == "cdrlogs" {  
xml {  
source =\> "message"  
store\_xml =\> "false"  
force\_array =\> "false"  
}

```
}

```

}

output {  
elasticsearch {  
hosts =\> "10.10.218.187:9200"  
index =\> "cdrlogs-%{+YYYY.MM.dd}"  
cacert =\> "/etc/logstash/root-ca.pem"  
user =\> "logstash"  
password =\> "logstash"  
ssl =\> true  
ssl\_certificate\_verification =\> false

```
  }
  stdout { codec => rubydebug }

```

}

and i have verified there is no errors in both the logstash and the elasticsearch file i have attached by xml file

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/5/05ec31e467ba226f046194baafcce61dcaec4008.png)

Please help me i am stuck kindly request

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 12, 2019, 1:23pm UTC](https://discuss.elastic.co/t/regarding-the-xml-file-issue/185392/2 "2019-06-12T13:23:55Z")

</div>

> [@dilipchiru](#):
>
> xml {  
> source =\> "message"  
> store\_xml =\> "false"  
> force\_array =\> "false"  
> }

If store\_xml is false, and you do not use xpath, then this does not modify the event -- it is just a very expensive no-op. Try specifying target and changing store\_xml to true.

---

<div class="post-metadata">

**Author:** ![dilipchiru](https://avatars.discourse-cdn.com/v4/letter/d/7ea924/32.png) [@dilipchiru](https://discuss.elastic.co/u/dilipchiru)\
**Post date:** [June 12, 2019, 1:28pm UTC](https://discuss.elastic.co/t/regarding-the-xml-file-issue/185392/3 "2019-06-12T13:28:49Z")

</div>

Thanks for the reply

i have changed according to it but if i want to mentioned the xpath there are more than 70 thousand lines in a record so how can i do for that

I have updated the filter  
filter {  
##interpret the message as XML  
if [type] == "cdrlogs" {  
xml {  
source =\> "message"  
store\_xml =\> "true"  
force\_array =\> "false"  
## target =\> "parsed"  
target =\> "xml\_content"  
}

```
}

```

}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2019, 1:28pm UTC](https://discuss.elastic.co/t/regarding-the-xml-file-issue/185392/4 "2019-07-10T13:28:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
