# TCP data splitted into several documents

**URL:** <https://discuss.elastic.co/t/tcp-data-splitted-into-several-documents/317986>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 2, 2022, 1:14pm UTC](https://discuss.elastic.co/t/tcp-data-splitted-into-several-documents/317986 "2022-11-02T13:14:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fangy](https://avatars.discourse-cdn.com/v4/letter/f/b2d939/32.png) [@Fangy](https://discuss.elastic.co/u/Fangy)\
**Post date:** [November 2, 2022, 1:14pm UTC](https://discuss.elastic.co/t/tcp-data-splitted-into-several-documents/317986/1 "2022-11-02T13:14:37Z")

</div>

Hi. I'm trying to ingest some new type of message. The message header is very similar to the syslog format, but the message itself is an xml format. Each line in the message ends with 0x0a (LF). These packets are ingested into elastic line by line. So each message (one tcp packet with data) is separated into several documents which makes no sense.

Of course, the ideal output for me will be parsed xml.

Is there a way to get rid of this framing?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2022, 3:15pm UTC](https://discuss.elastic.co/t/tcp-data-splitted-into-several-documents/317986/2 "2022-11-30T15:15:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
