# Work with xml in logstash

**URL:** <https://discuss.elastic.co/t/work-with-xml-in-logstash/324784>\
**Category:** Logstash\
**Created:** [February 6, 2023, 10:41am UTC](https://discuss.elastic.co/t/work-with-xml-in-logstash/324784 "2023-02-06T10:41:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sahere37](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Post date:** [February 6, 2023, 10:41am UTC](https://discuss.elastic.co/t/work-with-xml-in-logstash/324784/1 "2023-02-06T10:41:45Z")

</div>

Hi all, I have a xml data as below which is harvesting by filebeat and sending to logstash.

```auto
<event name="first check">
	<Data name="id">
		<Value>5</Value>
	</Data>
	<Data name="object_id">
		<Value>123</Value>
	</Data>
	<Data name="en">
		<Value>t</Value>
	</Data>
	<Data name="ex">
		<Value>5</Value>
	</Data>
	<Data name="cpt">
		<Value>0</Value>
	</Data>
	<Data name="pds">
		<Value>0</Value>
	</Data>
	<Data name="lr">
		<Value>0</Value>
	</Data>
	<Data name="wts">
		<Value>0</Value>
	</Data>
	<Data name="rt">
		<Value>1</Value>
	</Data>
	<Data name="object_name">
		<Value></Value>
	</Data>
	<Data name="st">
		<Value>hi</Value>
	</Data>
	<action name="mn">
		<Value>dw</Value>
	</action>
	<action name="sn">
		<Value>ad</Value>
	</action>
	<action name="hn">
		<Value>123</Value>
	</action>
	<action name="time1">
		<Value>11/14/2022 7:33:23 AM +00:00</Value>
	</action>
</event>

```

I want to store it as key value in elasticsearch as below:

```auto
id: 5
object_id: 123
en: t
ex: 5
cpt: 0
pds: 0
lr: 0
wts: 0
rt: 1
object_name: hh
st: hi
mn: dw
sn: ad
hn: 123
time1: 11/14/2022 7:33:23 AM +00:00

```

how can i parse this xml using logstash.the output of xml filter is not those which is expected. Any advice will be so appreciated.

```auto

xml { source => "message" 
      store_xml => true 
	  target => "theXML" 
	  force_array => false 

	  }

```

Regards

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 6, 2023, 7:05pm UTC](https://discuss.elastic.co/t/work-with-xml-in-logstash/324784/2 "2023-02-06T19:05:39Z")

</div>

You will need a ruby filter unless you know all the field names in advance (in which case you can use a mutate filter).

```
    xml { source => "message" target => "[@metadata][theXML]" }
    ruby {
        init => '
            def flatten (event, field)
                f = event.get(field)
                if f.respond_to? "each"
                    f.each { |x|
                        if x["Value"].is_a? Array and x["name"]
                            event.set(x["name"], x["Value"][0])
                        end
                    }
                end
            end
        '
        code => '
            flatten(event, "[@metadata][theXML][Data]")
            flatten(event, "[@metadata][theXML][action]")
        '
    }

```

will produce

```
      "time1" => "11/14/2022 7:33:23 AM +00:00",
         "ex" => "5",
        "wts" => "0",
"object_name" => nil,

```

etc.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2023, 7:05pm UTC](https://discuss.elastic.co/t/work-with-xml-in-logstash/324784/3 "2023-03-06T19:05:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
