# Unable to index xml file properly using logstash

**URL:** <https://discuss.elastic.co/t/unable-to-index-xml-file-properly-using-logstash/42318>\
**Category:** Logstash\
**Created:** [February 20, 2016, 11:05pm UTC](https://discuss.elastic.co/t/unable-to-index-xml-file-properly-using-logstash/42318 "2016-02-20T23:05:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sdaruna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sdaruna/32/7289_2.png) [@sdaruna](https://discuss.elastic.co/u/sdaruna)\
**Post date:** [February 20, 2016, 11:05pm UTC](https://discuss.elastic.co/t/unable-to-index-xml-file-properly-using-logstash/42318/1 "2016-02-20T23:05:52Z")

</div>

Hi,

I am trying to index big xml file.

Below is my xml file.

input {  
file {  
path =\> "/Users/srini/Downloads/imp/2016-01-27/\*.xml"  
start\_position =\> "beginning"  
}  
}

filter {  
xml {  
source =\> "message"  
target =\> "xmldata"  
store\_xml =\> "false"  
add\_tag =\> ["foo\_%{somefield}"]  
}  
}

output {  
elasticsearch {  
action =\> "index"  
hosts =\> "127.0.0.1"  
index =\> "srini2"

}  
stdout { codec =\> json }  
}

I have nested data.  
The data when i searched in elasticsearch, it is indexing each line.  
How can i make sure,

1. Is there any mistake with my logstash config file.?
2. index whole file instead of line. ?

Thank You,  
Regards,  
Srini.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 22, 2016, 6:48pm UTC](https://discuss.elastic.co/t/unable-to-index-xml-file-properly-using-logstash/42318/2 "2016-02-22T18:48:49Z")

</div>

The file input isn't geared towards this use case. You need to use a multiline codec to join all lines of the file into a single event or a completely different input plugin that can slurp the whole file at once (like [exec](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-exec.html)).

---

<div class="post-metadata">

**Author:** ![sdaruna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sdaruna/32/7289_2.png) [@sdaruna](https://discuss.elastic.co/u/sdaruna)\
**Post date:** [February 22, 2016, 6:52pm UTC](https://discuss.elastic.co/t/unable-to-index-xml-file-properly-using-logstash/42318/3 "2016-02-22T18:52:16Z")

</div>

Hi @magnusbaeck,

Thanks for the details. I have resolved with using multilines. I forgot to close the topic.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:10am UTC](https://discuss.elastic.co/t/unable-to-index-xml-file-properly-using-logstash/42318/4 "2017-07-06T05:10:18Z")

</div>


