# Unable to load the xml document to elastic search

**URL:** <https://discuss.elastic.co/t/unable-to-load-the-xml-document-to-elastic-search/267403>\
**Category:** Logstash\
**Created:** [March 16, 2021, 5:08pm UTC](https://discuss.elastic.co/t/unable-to-load-the-xml-document-to-elastic-search/267403 "2021-03-16T17:08:55Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sdeven](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@sdeven](https://discuss.elastic.co/u/sdeven)\
**Post date:** [March 16, 2021, 5:08pm UTC](https://discuss.elastic.co/t/unable-to-load-the-xml-document-to-elastic-search/267403/1 "2021-03-16T17:08:56Z")

</div>

`Hi Team, I am trying to load the whole xml document to elastic search using logstash. I don't see any errors in the logstash console, and the document is not there in elastic search also. my config file below.`

```auto
input {
  file {
    path => "/Users/userid/POC/ELK/data/data.xml"
    start_position => "beginning"
    sincedb_path => "nul"
      type => "xml"
    codec => multiline
      {
       pattern => "<Document"
       negate => "true"
       what => "previous"
       auto_flush_interval=>2
      }
    }
}

filter {
    xml {
      source => "message"
      remove_namespaces => true
      target => "doc"
  }
}
output
{
	stdout {
	}

 	elasticsearch {
    hosts => ["localhost:9200"]
    index => "document"
  }

}

```

---

<div class="post-metadata">

**Author:** ![sdeven](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@sdeven](https://discuss.elastic.co/u/sdeven)\
**Post date:** [March 16, 2021, 5:12pm UTC](https://discuss.elastic.co/t/unable-to-load-the-xml-document-to-elastic-search/267403/2 "2021-03-16T17:12:45Z")

</div>

Sample Xml document

```auto
<?xml version="1.0" encoding="UTF-8"?>
<Document> 
    <recordTarget>
          <role>
                   .....
                  ...... have multiple internal tags....
          </role>
    </recordTarget>
 </Document>

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 16, 2021, 6:12pm UTC](https://discuss.elastic.co/t/unable-to-load-the-xml-document-to-elastic-search/267403/3 "2021-03-16T18:12:28Z")

</div>

> [@sdeven](#):
>
> ```auto
> xml {
> source => "ClinicalDocument"
> 
> ```

You do not have a field called [ClinicalDocument]. The file input will create a field called [message].

If you do not want the in-memory sincedb persisted across restarts then use `sincedb_path => "NUL"` on Windows and `sincedb_path => "/dev/null"` on UNIX.

---

<div class="post-metadata">

**Author:** ![sdeven](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@sdeven](https://discuss.elastic.co/u/sdeven)\
**Post date:** [March 17, 2021, 2:05am UTC](https://discuss.elastic.co/t/unable-to-load-the-xml-document-to-elastic-search/267403/4 "2021-03-17T02:05:55Z")

</div>

Hi @Badger , Thanks for your response. I have updated the config with correct tag. Also, I tried using the Source as message, still I am getting the same response, I don't see any error message but not able to see it in elastic search.

---

<div class="post-metadata">

**Author:** ![sdeven](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@sdeven](https://discuss.elastic.co/u/sdeven)\
**Post date:** [March 18, 2021, 8:39pm UTC](https://discuss.elastic.co/t/unable-to-load-the-xml-document-to-elastic-search/267403/5 "2021-03-18T20:39:57Z")

</div>

Hi @Badger I was able to see the xml in the kibana after running the logstash command using sudo command. But the XML parsing is failing at different stages. Single XML file created 7 events with the below tags **multiline, multiline\_codec\_max\_lines\_reached, \_xmlparsefailure**. I would like to create a single event for the xml content. Below is my current config file.

```auto
input {
    file {
        path => "/Users/user/POC/ELK/data/data.xml"
        start_position => "beginning"
        sincedb_path => "/dev/null"
        codec => multiline {
            pattern => "<Document"
            negate => "true"
            what => "previous"
            auto_flush_interval => 1
            max_lines => 2000
        }
    }
}
filter {
    xml {
      source => "message"
      target => "xml_content"
    }
}
output {
    stdout { codec => rubydebug }
    elasticsearch{
      hosts => ["localhost:9200"]
      index => "document"
    }

}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 18, 2021, 10:24pm UTC](https://discuss.elastic.co/t/unable-to-load-the-xml-document-to-elastic-search/267403/6 "2021-03-18T22:24:15Z")

</div>

> [@sdeven](#):
>
> multiline\_codec\_max\_lines\_reached

If the multiline codec stops accumulating lines before it reaches the next \<Document element then it is not going to be valid XML and the xml filter will not be able to parse it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 15, 2021, 10:24pm UTC](https://discuss.elastic.co/t/unable-to-load-the-xml-document-to-elastic-search/267403/7 "2021-04-15T22:24:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
