# Xml filter with keyvalue pair

**URL:** <https://discuss.elastic.co/t/xml-filter-with-keyvalue-pair/157613>\
**Category:** Logstash\
**Created:** [November 20, 2018, 10:22pm UTC](https://discuss.elastic.co/t/xml-filter-with-keyvalue-pair/157613 "2018-11-20T22:22:53Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [November 21, 2018, 6:11am UTC](https://discuss.elastic.co/t/xml-filter-with-keyvalue-pair/157613/2 "2018-11-21T06:11:21Z")

</div>

hope this helps you,

> [@Is it possible to change output structure](https://discuss.elastic.co/t/is-it-possible-to-change-output-structure/153759/17):
>
> The input code as per your requirement is as follows, input { file { path =\> "D:/xxxxx/ELKStack/sample.xml" start\_position =\> "beginning" sincedb\_path =\> "NUL" codec =\> multiline { pattern =\> "" negate =\> "true" what =\> "previous" auto\_flush\_interval =\> 1 max\_lines =\> 333333 } } } filter { xml { source =\> "message" target =\> "parsed" store\_xml =\> "false" xpath =\> [ "/system/Report/ReportHost/@ip","ip", "/system/Report/ReportHost/HostProperties/tag/@pluginname","pluginname", …

---

_[View the full topic](https://discuss.elastic.co/t/xml-filter-with-keyvalue-pair/157613)._
