# Wich is the best way to parse logs with XML seccion

**URL:** <https://discuss.elastic.co/t/wich-is-the-best-way-to-parse-logs-with-xml-seccion/179556>\
**Category:** Logstash\
**Created:** [May 3, 2019, 3:14pm UTC](https://discuss.elastic.co/t/wich-is-the-best-way-to-parse-logs-with-xml-seccion/179556 "2019-05-03T15:14:14Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 3, 2019, 6:01pm UTC](https://discuss.elastic.co/t/wich-is-the-best-way-to-parse-logs-with-xml-seccion/179556/2 "2019-05-03T18:01:25Z")

</div>

You could try something like

```
if "xml" in [message] {
        dissect { mapping => { "message" => "%{}[%{}]%{}[%{[@metadata][xml]}]%{}" } }
}

```

Then if the XML is valid (what you have shown is not) you could parse it with an xml filter

```
xml { source => "[@metadata][xml]" target => "theXML" }
```

---

_[View the full topic](https://discuss.elastic.co/t/wich-is-the-best-way-to-parse-logs-with-xml-seccion/179556)._
