# Remove xml-tags during parsing

**URL:** <https://discuss.elastic.co/t/remove-xml-tags-during-parsing/71713>\
**Category:** Logstash\
**Created:** [January 16, 2017, 10:19am UTC](https://discuss.elastic.co/t/remove-xml-tags-during-parsing/71713 "2017-01-16T10:19:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Denny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denny/32/9157_2.png) [@Denny](https://discuss.elastic.co/u/Denny)\
**Post date:** [January 16, 2017, 10:19am UTC](https://discuss.elastic.co/t/remove-xml-tags-during-parsing/71713/1 "2017-01-16T10:19:56Z")

</div>

Hello,

So far I've only experience with indexing csv-files with Logstash into Elasticsearch. Now I have a couple of xml-files which I want to index and fortunately it was not that difficult. With the most basic conf I've managed to get the data in Elasticsearch:

```
filter
{
    xml {
      source => "VINAnalysis"
      remove_tag => ["%{SystemInfo}"]
    }
}

```

The tag VINAnalysis encloses the whole xml-file so I've used that one as my source. When I look at the data in Kibana I see that Logstash has indexed all xml-tags. I want to get rid of those because I don't want them searchable.

I thought I can remove those tags with the remove\_tag option and one of the XML-tags is

`<SystemInfo>data: data</Systeminfo>`.

I've added it to my conf which you can see above but the tag is still being indexed. What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 16, 2017, 12:09pm UTC](https://discuss.elastic.co/t/remove-xml-tags-during-parsing/71713/2 "2017-01-16T12:09:19Z")

</div>

Perhaps it would be a better idea to use the `xpath` option to selectively save things you _do_ want to save, instead of extracting everything and ripping out the boring stuff?

> ```
> remove_tag => ["%{SystemInfo}"]
> 
> ```

There are several reasons why this doesn't work.

- "Tags" in Logstash have nothing to do with XML tags in parsed XML documents.
- You should use use the `%{foo}` notation when you want to expand the _contents_ of a field. In this case you want to reference a field by name.
- The `SystemInfo` field is a nested field so you need to access it via e.g. `[VINAnalysis][SystemInfo]` or whatever the structure looks like.

---

<div class="post-metadata">

**Author:** ![Denny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/denny/32/9157_2.png) [@Denny](https://discuss.elastic.co/u/Denny)\
**Post date:** [January 16, 2017, 12:42pm UTC](https://discuss.elastic.co/t/remove-xml-tags-during-parsing/71713/3 "2017-01-16T12:42:46Z")

</div>

Thank you for clearing it up!

I'm playing around with xpath and have indexed the file again but I'm not sure what I should expect in the results. This is the structure of the file:

```
<VINAnalysis>
<BasicInfo>
<Info1>Hash:</Info1><InfoVale>0000000000AAAAA</InfoVale>
<Info2>More than 1 found:</Info2><InfoVale>No</InfoVale>
<Info3>Save Time:</Info3><InfoVale>2016-11-25 15:38:30</InfoVale>

```

This is a part of my conf:

```
filter
{
    xml {
      source => "VINAnalysis"
      xpath => {
      "//VINAnalysis/BasicInfo/Info1/InfoVale" => "hash"
      "//VINAnalysis/BasicInfo/Info2"/InfoVale => "more_than_1_found"
       "//VINAnalysis/BasicInfo/Info3"/InfoVale => "save_time"
               }
          }
}

```

But I still see the data with the tags in Kibana.

Any ideas what I'm doing wrong?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 16, 2017, 1:00pm UTC](https://discuss.elastic.co/t/remove-xml-tags-during-parsing/71713/4 "2017-01-16T13:00:24Z")

</div>

Make sure you set `store_xml => false`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2017, 1:00pm UTC](https://discuss.elastic.co/t/remove-xml-tags-during-parsing/71713/5 "2017-02-13T13:00:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
