# Unable to parse the xml tag and create a field in Elastic Search

**URL:** <https://discuss.elastic.co/t/unable-to-parse-the-xml-tag-and-create-a-field-in-elastic-search/269645>\
**Category:** Logstash\
**Created:** [April 8, 2021, 8:41pm UTC](https://discuss.elastic.co/t/unable-to-parse-the-xml-tag-and-create-a-field-in-elastic-search/269645 "2021-04-08T20:41:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sdeven](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@sdeven](https://discuss.elastic.co/u/sdeven)\
**Post date:** [April 8, 2021, 8:41pm UTC](https://discuss.elastic.co/t/unable-to-parse-the-xml-tag-and-create-a-field-in-elastic-search/269645/1 "2021-04-08T20:41:05Z")

</div>

Hi,  
I am using the http plugin in my logstash.conf file, where I am getting a XML document. I have to extract a tag from the XML document and make it as a field in elastic search. I am not getting any errors but the filed is not getting created when I see the kibana dashboard.

Logstash.config

```auto
Input {
 http {
    host => "0.0.0.0"
    port => "8080"
  }
}

filter {
    xml {
      source => "message"
      store_xml => false
      remove_namespaces => true
      xpath =>["/Document/student/id", "studentID"]
    }
}

output {
stdout { codec => rubydebug }
elasticsearch{
  hosts => ["localhost:9200"]
  index => "document"
  type => "patients"

}
}

```

xml Input

```auto
<?xml version="1.0" encoding="UTF-8"?>
<Document> 
    <student>
         <id>1234567</id>
    </student>
    <recordTarget>
          <role>
                   .....
                  ...... have multiple internal tags....
          </role>
    </recordTarget>
 </Document>

```

Can you please point out what is the mistake I am doing here. Thanks in advance

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 8, 2021, 10:37pm UTC](https://discuss.elastic.co/t/unable-to-parse-the-xml-tag-and-create-a-field-in-elastic-search/269645/2 "2021-04-08T22:37:34Z")

</div>

In the rubydebug output, what does the [message] field look like?

---

<div class="post-metadata">

**Author:** ![sdeven](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@sdeven](https://discuss.elastic.co/u/sdeven)\
**Post date:** [April 9, 2021, 3:07pm UTC](https://discuss.elastic.co/t/unable-to-parse-the-xml-tag-and-create-a-field-in-elastic-search/269645/3 "2021-04-09T15:07:49Z")

</div>

@Badger below is the content of the message in the stdout

```auto
"message" => "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<Document>\n <student> \n <Id>12345678</Id>\n </student>\n <recordTarget>\n <role> \n
                   .....
                  ...... have multiple internal tags....
          </role>\n </recordTarget>\n </Document>\n"

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 9, 2021, 4:23pm UTC](https://discuss.elastic.co/t/unable-to-parse-the-xml-tag-and-create-a-field-in-elastic-search/269645/4 "2021-04-09T16:23:04Z")

</div>

> [@sdeven](#):
>
> `xpath =>["/Document/student/id", "studentID"]`

The document you showed has "/Document/student/Id", not "/Document/student/id". XML tags are case sensitive.

---

<div class="post-metadata">

**Author:** ![sdeven](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@sdeven](https://discuss.elastic.co/u/sdeven)\
**Post date:** [April 9, 2021, 4:38pm UTC](https://discuss.elastic.co/t/unable-to-parse-the-xml-tag-and-create-a-field-in-elastic-search/269645/5 "2021-04-09T16:38:17Z")

</div>

@Badger Haa.. Silly mistake, Thanks alot for finding it. One more question on the same. If I have to use the same ID as an Attribute in the like the below

```auto
<?xml version="1.0" encoding="UTF-8"?>
<Document studentId="1234567"> 
    <recordTarget>
          <role>
                   .....
                  ...... have multiple internal tags....
          </role>
    </recordTarget>
 </Document>

```

can I use the Xpath as below

```auto
xpath =>["/Document/@studentId", "studentID"]

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 9, 2021, 4:40pm UTC](https://discuss.elastic.co/t/unable-to-parse-the-xml-tag-and-create-a-field-in-elastic-search/269645/6 "2021-04-09T16:40:49Z")

</div>

I would expect that to work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2021, 4:41pm UTC](https://discuss.elastic.co/t/unable-to-parse-the-xml-tag-and-create-a-field-in-elastic-search/269645/7 "2021-05-07T16:41:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
