# XML filter issue

**URL:** <https://discuss.elastic.co/t/xml-filter-issue/124012>\
**Category:** Logstash\
**Created:** [March 15, 2018, 1:55am UTC](https://discuss.elastic.co/t/xml-filter-issue/124012 "2018-03-15T01:55:26Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [March 15, 2018, 1:55am UTC](https://discuss.elastic.co/t/xml-filter-issue/124012/1 "2018-03-15T01:55:26Z")

</div>

I am getting started with the XML filter plugin. Here is my config:

```
filter {
  xml {
    source => "message"
    store_xml => false
  }
}

```

Ideally I want to have Logstash just convert the XML to JSON (ie. convert all the tags to JSON keys and the data inside them to the values). Is there any way to do this?

Currently it just outputs the entire XML event to the `message` field but doesn't change it in any way.

---

<div class="post-metadata">

**Author:** ![Vaibhav\_Palve](https://avatars.discourse-cdn.com/v4/letter/v/2acd7d/32.png) [@Vaibhav\_Palve](https://discuss.elastic.co/u/Vaibhav_Palve)\
**Post date:** [March 15, 2018, 8:36am UTC](https://discuss.elastic.co/t/xml-filter-issue/124012/2 "2018-03-15T08:36:31Z")

</div>

You can use Xpath to extract the specific fields you want to extract from the xml message.

---

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [March 15, 2018, 11:11am UTC](https://discuss.elastic.co/t/xml-filter-issue/124012/3 "2018-03-15T11:11:01Z")

</div>

I'm not sure what the format of each message is though.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 15, 2018, 2:30pm UTC](https://discuss.elastic.co/t/xml-filter-issue/124012/4 "2018-03-15T14:30:44Z")

</div>

Are you saying each xml you intend to ingest could have very different structures? Do you have a sample file to share with us?

---

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [March 15, 2018, 2:46pm UTC](https://discuss.elastic.co/t/xml-filter-issue/124012/5 "2018-03-15T14:46:57Z")

</div>

Correct. I can't share the files, but yes, the data structures would be different.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 15, 2018, 3:09pm UTC](https://discuss.elastic.co/t/xml-filter-issue/124012/6 "2018-03-15T15:09:19Z")

</div>

That's a problem then, they have to have a common structure that you could build XPaths off of. BTW, when I say common structure, I mean the same XML tag structure.  
`<tag><subtag><tertiarytag></tertiarytag></subtag></tag>`

It can be pretty formatted in any kind of way

```
<tag>
<subtag><tertiarytag></tertiarytag></subtag>
</tag>

```

or

> ```
> <tag>
> <subtag>
> <tertiarytag></tertiarytag>
> </subtag>
> </tag>
> 
> ```

etc...

---

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [March 15, 2018, 3:52pm UTC](https://discuss.elastic.co/t/xml-filter-issue/124012/7 "2018-03-15T15:52:47Z")

</div>

Okay, so is there a way to have an external program filter it? For example, I could use this: [https://hackage.haskell.org/package/xml-to-json](https://hackage.haskell.org/package/xml-to-json)

to convert all the XML to JSON. The only issue is I see that `exec` is only for outputs, not filters.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 15, 2018, 5:15pm UTC](https://discuss.elastic.co/t/xml-filter-issue/124012/9 "2018-03-15T17:15:18Z")

</div>

> [@arisbanach](#):
>
> I want to have Logstash just convert the XML to JSON

Well you get structured data in the event if you set store\_xml to be true. And logstash can output that as JSON.

---

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [March 15, 2018, 5:46pm UTC](https://discuss.elastic.co/t/xml-filter-issue/124012/10 "2018-03-15T17:46:09Z")

</div>

That worked perfectly! I just didn't think `store_xml` would be relevant based on the name. Thank you so much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2018, 9:46am UTC](https://discuss.elastic.co/t/xml-filter-issue/124012/12 "2018-04-13T09:46:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
