# XML Confusion

**URL:** <https://discuss.elastic.co/t/xml-confusion/78558>\
**Category:** Logstash\
**Created:** [March 14, 2017, 4:21pm UTC](https://discuss.elastic.co/t/xml-confusion/78558 "2017-03-14T16:21:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kvetch](https://avatars.discourse-cdn.com/v4/letter/k/85e7bf/32.png) [@Kvetch](https://discuss.elastic.co/u/Kvetch)\
**Post date:** [March 14, 2017, 4:21pm UTC](https://discuss.elastic.co/t/xml-confusion/78558/1 "2017-03-14T16:21:05Z")

</div>

Hello,  
I am trying to parse an xml file but am confused on the best way to tackle it. I see some folks using split to process and xml file and others using xpath. My xml file looks like the following:

> ```
> <blah>
> <blahlist>
> <stuff>
> <Id>1234</Id>
> <Epoch>1488847761</Epoch>
> </stuff>
> <stuff>
> <Id>1235</Id>
> <Epoch>1499947761</Epoch>
> </stuff>
> </blahlist>
> </blah>
> 
> ```

I have tried a handful of variations for logstash, such as

> input {  
> file {  
> path =\> "test.xml"  
> start\_position =\> beginning  
> sincedb\_path =\> "NUL"  
> codec =\> multiline  
> {  
> pattern =\> "\<blah"  
> negate =\> true  
> what =\> "previous"  
> }  
> }  
> }  
> filter {  
> xml {  
> store\_xml =\> "false"  
> source =\> "message"  
> xpath =\> ["/blah/blahlist/stuff/Id/text()", "Id"]  
> xpath =\> ["/blah/blahlist/stuff/Epoch/text()", "Epoch"]  
> force\_array =\> "false"  
> }  
> mutate {  
> remove\_field =\> 'message'  
> }  
> }

This however doesn't make a entry for each stuff. It puts each element from stuff into an array. Like such

> {  
> "path" =\> "test.xml",  
> "@timestamp" =\> 2017-03-14T16:14:57.277Z,  
> "@version" =\> "1",  
> "host" =\> "Coompooter.local",  
> "Epoch" =\> [  
> [0] "1488847761",  
> [1] "1499947761"  
> ],  
> "Id" =\> [  
> [0] "1234",  
> [1] "1235"  
> ],  
> "tags" =\> [  
> [0] "multiline"  
> ]  
> }

How can I read the xml and make it have an entry for each "stuff\>" and "/stuff\>" it reads. I think so it looks like:  
{

> ```
> "path" => "test.xml",
> "@timestamp" => 2017-03-14T16:14:57.277Z,
> "@version" => "1",
> "host" => "Coompooter.local",
> "Epoch" => ["1499947761"],
> "Id" => ["1235"],
> "tags" => [
> [0] "multiline"
> ]
> 
> ```
> 
> }  
> {  
> "path" =\> "test.xml",  
> "@timestamp" =\> 2017-03-14T16:14:57.277Z,  
> "@version" =\> "1",  
> "host" =\> "Coompooter.local",  
> "Epoch" =\> ["1488847761"],  
> "Id" =\> ["1234"],  
> "tags" =\> [  
> [0] "multiline"  
> ]  
> }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2017, 6:35am UTC](https://discuss.elastic.co/t/xml-confusion/78558/2 "2017-03-15T06:35:49Z")

</div>

Write some code in a ruby filter to turn

```nohighlight
"Epoch": [
  "1488847761",
  "1499947761"
],
"Id": [
  "1234",
  "1235"
],

```

into

```nohighlight
"Whatever": [
  {
    "Epoch": "1488847761",
    "Id": "1234"
  },
  {
    "Epoch": "1488847761",
    "Id": "1235"
  }
]

```

then use a split filter to splice one such event into multiple events.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2017, 6:35am UTC](https://discuss.elastic.co/t/xml-confusion/78558/3 "2017-04-12T06:35:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
