# Trouble parsing xml file in logstash

**URL:** <https://discuss.elastic.co/t/trouble-parsing-xml-file-in-logstash/157874>\
**Category:** Logstash\
**Created:** [November 22, 2018, 12:28pm UTC](https://discuss.elastic.co/t/trouble-parsing-xml-file-in-logstash/157874 "2018-11-22T12:28:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shubh235](https://avatars.discourse-cdn.com/v4/letter/s/7cd45c/32.png) [@shubh235](https://discuss.elastic.co/u/shubh235)\
**Post date:** [November 22, 2018, 12:28pm UTC](https://discuss.elastic.co/t/trouble-parsing-xml-file-in-logstash/157874/1 "2018-11-22T12:28:43Z")

</div>

I am trying to load a basic xml file into logstash but somehow, the file is not loaded. No exceptions are thrown and I am running Logstash through command prompt and not as a service. Could you please check and help me figure out what I am doing wrong.

Below is my xml file :

```
<LogEntry>
<Terminal>SYSTEM</Terminal>
<EvTxt_1>6940</EvTxt_1>
<EvTxt_2>0</EvTxt_2>
<EvTxt_3>0</EvTxt_3>
<EvTxt_4>0</EvTxt_4>
<EvTxt_5>0</EvTxt_5>
</LogEntry>

```

And, my config file looks like this :

```
input {

 file {

  path => "C:\xml_test\test4.xml"
  start_position => "beginning"
  sincedb_path => "null"
  codec => multiline
  {
   pattern => "^<\?LogEntry .*\>"
   negate => false
   what => "next"
  }
 }
}

filter {
    xml {
        store_xml => false
        source => "message"
        target => "xml_content"
        xpath => ["/LogEntry/Terminal/text()","terminal"]
    }
}

output {
  stdout { codec => json_lines }
  elasticsearch {
  "hosts" => ["http://localhost:9200"]
  "index" => "xml_test"
  "document_type" => "data"
  }
}
```

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 22, 2018, 12:35pm UTC](https://discuss.elastic.co/t/trouble-parsing-xml-file-in-logstash/157874/2 "2018-11-22T12:35:46Z")

</div>

Try the following:

```
input {

 file {

  path => "C:/xml_test/test4.xml"
  start_position => "beginning"
  sincedb_path => "NUL"
  codec => multiline
  {
   pattern => "^<\?LogEntry .*\>"
   negate => false
   what => "next"
  }
 }
}
```

---

<div class="post-metadata">

**Author:** ![shubh235](https://avatars.discourse-cdn.com/v4/letter/s/7cd45c/32.png) [@shubh235](https://discuss.elastic.co/u/shubh235)\
**Post date:** [November 22, 2018, 1:07pm UTC](https://discuss.elastic.co/t/trouble-parsing-xml-file-in-logstash/157874/3 "2018-11-22T13:07:03Z")

</div>

Thank you. This works and now I have indexed this xml file in Elasticsearch. However, all the tags are stored now in message field.

Example : `"message": "<EvTxt_5>0</EvTxt_5>\r"`

How can I get the values of the tags to be stored in elasticsearch with field name as tag name ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2018, 1:07pm UTC](https://discuss.elastic.co/t/trouble-parsing-xml-file-in-logstash/157874/4 "2018-12-20T13:07:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
