# XML import

**URL:** <https://discuss.elastic.co/t/xml-import/154273>\
**Category:** Logstash\
**Created:** [October 27, 2018, 7:49am UTC](https://discuss.elastic.co/t/xml-import/154273 "2018-10-27T07:49:07Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrncgirc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrncgirc/32/45055_2.png) [@mrncgirc](https://discuss.elastic.co/u/mrncgirc)\
**Post date:** [October 27, 2018, 7:49am UTC](https://discuss.elastic.co/t/xml-import/154273/1 "2018-10-27T07:49:07Z")

</div>

# XML Import with Logstash

Hi there

I have read about all XML filter import examples I can find. However, I just cannot figure out how to get this specific xml format imported through logstash.

## Use case

The government of Denmark provides a public XML feed with data from the motorregistry. I would like to import this data into elasticsearch.

I wish to store it, to play with the analysis and types of data..

Anyway, the format contains nodes with danish names from the source (sorry).

### XML Format

The repeating element for each registration is the node: ns:Statistik

I would like to just import the entire xml tree within ns:Statistik into a document type of the name "vehicle". The nodes should be converted into fields and the content with in, the value / nested object.

The XML file format can be found here:

> <https://gist.github.com/michaelrachlitz/16e87f4e8b0f6ffb8b63e7e5f8e98b56>

### Issue

Hardly any of my logstash.conf is working. I have gotten two different results when importing. I have succesfully imported the entire xml file into 1 document. I have succesfully imported each line into seperate documents.

But I don't understand the documentation of the XML filter apparently. CSV import etc. I know, and it seems so simply in comparison. The XML is really difficult to understand, and I cannot get any of the examples I've found on the forum nor stackoverflow to work either.

Hopefully one of you guys could provide me with a complete logstash conf, and from that I hopefully could learn how to do this with the XML filter in the future.

Thanks for reading

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [October 27, 2018, 11:28am UTC](https://discuss.elastic.co/t/xml-import/154273/2 "2018-10-27T11:28:14Z")

</div>

I'm on mobile, so I'll keep this short and untested. Your configuration will probably have to look similar to this:

```
filter {
  xml {
    target => "doc" 
    source => "message"
  }
  mutate { 
    remove_field => ["message"] 
  }
  split {
    field => "[doc][ns:StatistikSamling][ns:Statistik]"
  } 
}

```

The split filter will separate the documents like you want to do. And then you have to rename and delete fields until you have a nice structure.

(If you have a configuration that is not working and are looking for help, it's always good to post what you've got. Solving a problem is easier, if you have something to build on. And one is probably more motivated, if the post is not basically saying 'Please do my job for me' 🙂)

---

<div class="post-metadata">

**Author:** ![mrncgirc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrncgirc/32/45055_2.png) [@mrncgirc](https://discuss.elastic.co/u/mrncgirc)\
**Post date:** [October 27, 2018, 12:20pm UTC](https://discuss.elastic.co/t/xml-import/154273/3 "2018-10-27T12:20:45Z")

</div>

Hi Jenni,

I will take your feedback into account. It was in no way intended for a "Please do my job for me", I wish to learn how to work with this xml import and I have attempted for weeks now, also reaching out on IRC.

Nevertheless I appreciate your feedback and I have had a go on it. With your example it is clear to me first of all, how I misunderstood the XML filter documentation entirely. I attempted to make multiple nodes with xpath.

I still does not work entirely, but I would like to fiddle a little with your example and the split function. I am having the error \_xmlparsefailure and \_split\_type\_failure, but I think I can solve these.

Thank you for your example, it was just what I needed to move on

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [October 27, 2018, 12:37pm UTC](https://discuss.elastic.co/t/xml-import/154273/4 "2018-10-27T12:37:34Z")

</div>

I hope, I didn't offend you with that last line. I didn't mean any harm 😄 Feel free to ask, if you get stuck again!

---

<div class="post-metadata">

**Author:** ![mrncgirc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrncgirc/32/45055_2.png) [@mrncgirc](https://discuss.elastic.co/u/mrncgirc)\
**Post date:** [October 27, 2018, 7:09pm UTC](https://discuss.elastic.co/t/xml-import/154273/5 "2018-10-27T19:09:11Z")

</div>

Absolutely not, just wanted to clarify 🙂

Thank you! I will reach out if I get stuck. Kid is a sleep now, so I am giving it a go

---

<div class="post-metadata">

**Author:** ![mrncgirc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrncgirc/32/45055_2.png) [@mrncgirc](https://discuss.elastic.co/u/mrncgirc)\
**Post date:** [October 29, 2018, 10:30am UTC](https://discuss.elastic.co/t/xml-import/154273/6 "2018-10-29T10:30:57Z")

</div>

Hi Jenni,

I think I've located my issue, but unable to figure out how exactly to solve it.

It seems my codec is not matching each xml "document" node correctly.

I've attempted with:  
pattern =\> "^\<ns:ESStatistikListeModtag\_I\>"  
pattern =\> "^\<ns:Statistisk\>"  
(also tested without ns)

With multiline I just cant make it import anything, if I remove it I get each line imported separately.

```
input {
file {
    path => "/usr/share/logstash/files/test.xml"
    start_position => "beginning"
	sincedb_path => "/dev/null"
	stat_interval => 1
    codec => multiline {
        pattern => "^<ns:ESStatistikListeModtag_I>"
        negate => "true"
        what => "previous"
    }
}

```

}

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [October 29, 2018, 11:09am UTC](https://discuss.elastic.co/t/xml-import/154273/7 "2018-10-29T11:09:07Z")

</div>

Your ESStatistikListeModtag\_I node has an attribute, so `^<ns:ESStatistikListeModtag_I>` (the tag is closed directly after its name) will never match.

---

<div class="post-metadata">

**Author:** ![humalog](https://avatars.discourse-cdn.com/v4/letter/h/cc9497/32.png) [@humalog](https://discuss.elastic.co/u/humalog)\
**Post date:** [October 29, 2018, 11:12am UTC](https://discuss.elastic.co/t/xml-import/154273/8 "2018-10-29T11:12:20Z")

</div>

You need to understand the [Multiline codec plugin](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html). Your mistake happens at the what option.

---

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [October 29, 2018, 11:16am UTC](https://discuss.elastic.co/t/xml-import/154273/9 "2018-10-29T11:16:34Z")

</div>

hope this code helps you,

> [@Is it possible to change output structure](https://discuss.elastic.co/t/is-it-possible-to-change-output-structure/153759/17):
>
> The input code as per your requirement is as follows, input { file { path =\> "D:/xxxxx/ELKStack/sample.xml" start\_position =\> "beginning" sincedb\_path =\> "NUL" codec =\> multiline { pattern =\> "" negate =\> "true" what =\> "previous" auto\_flush\_interval =\> 1 max\_lines =\> 333333 } } } filter { xml { source =\> "message" target =\> "parsed" store\_xml =\> "false" xpath =\> [ "/system/Report/ReportHost/@ip","ip", "/system/Report/ReportHost/HostProperties/tag/@pluginname","pluginname", …

---

<div class="post-metadata">

**Author:** ![mrncgirc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrncgirc/32/45055_2.png) [@mrncgirc](https://discuss.elastic.co/u/mrncgirc)\
**Post date:** [October 29, 2018, 6:04pm UTC](https://discuss.elastic.co/t/xml-import/154273/10 "2018-10-29T18:04:18Z")

</div>

Yea you we're absolutely right. I've found the solution now.

Got it all working now. Thanks a ton for your time Jenni

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 26, 2018, 6:04pm UTC](https://discuss.elastic.co/t/xml-import/154273/11 "2018-11-26T18:04:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
