XML encoded logs from Mcafee EPO logs to logstash

Use a grok filter to extract timestamp and other parts of the message to separate fields. One of the fields should contain the XML payload and that's the field you then reference in your xml filter.