# XML into JSON value

**URL:** <https://discuss.elastic.co/t/xml-into-json-value/352933>\
**Category:** Logstash\
**Created:** [February 9, 2024, 12:42pm UTC](https://discuss.elastic.co/t/xml-into-json-value/352933 "2024-02-09T12:42:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![martel](https://avatars.discourse-cdn.com/v4/letter/m/b77776/32.png) [@martel](https://discuss.elastic.co/u/martel)\
**Post date:** [February 9, 2024, 12:42pm UTC](https://discuss.elastic.co/t/xml-into-json-value/352933/1 "2024-02-09T12:42:58Z")

</div>

Hey,

If i have a Json message, into has an element "error" : "\<?xml version=\"1.0\" encoding=\"UTF-8\"?\> zefzefzfzef "

how can extract and parse XML for create a sub-doc with all element xml  
example :  
"json" : "valueJson"  
"error" : {  
"xmlRoot" : {  
"a" : "zefzefzfzef"  
}  
}

into logstash config :  
in my filter {  
json {  
source =\> "message"  
}  
xxx  
xxxx  
xml {  
source =\> "message.error"  
target =\> "xmlFormatted"  
}  
} // end filter

thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 9, 2024, 3:50pm UTC](https://discuss.elastic.co/t/xml-into-json-value/352933/2 "2024-02-09T15:50:44Z")

</div>

Please edit your post to show the actual value of the XML. In the text edit box select the XML and click on \</\> in the tool bar. Otherwise the XML will be consumed by the browser as if it were HTML.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 10, 2024, 1:21pm UTC](https://discuss.elastic.co/t/xml-into-json-value/352933/3 "2024-02-10T13:21:46Z")

</div>

Can you put the message or event.original field?

---

<div class="post-metadata">

**Author:** ![martel](https://avatars.discourse-cdn.com/v4/letter/m/b77776/32.png) [@martel](https://discuss.elastic.co/u/martel)\
**Post date:** [February 10, 2024, 3:22pm UTC](https://discuss.elastic.co/t/xml-into-json-value/352933/4 "2024-02-10T15:22:43Z")

</div>

i have this xml example into value of one element Json.

```auto
"<?xml version=\"1.0\" encoding=\"UTF-8\"?>
<begin>
   <error>
           <a>zeffzefzef</a>
  </error>
</bebin>"

```

simple ? if i do in filter first JSON

```auto
json {
      source => "message"
}

```

i have Json correctly structured into Elasticseach.  
now if i do a second into the same filter:

```auto
xml {
   source => "message.error"
   target => "xmlFormatted"
}

```

normaly logstash take the message (in Json structure) and now the XML function take "message"-\>"error" and Parse xml for add fields from xml .

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 10, 2024, 9:20pm UTC](https://discuss.elastic.co/t/xml-into-json-value/352933/5 "2024-02-10T21:20:05Z")

</div>

Let's assume you have JSON like this:

```auto
{
    "json" : "valueJson",
	"xmlRoot" : "<?xml version=\"1.0\" encoding=\"UTF-8\"?>
    <begin>
       <error>
           <a>zeffzefzef</a>
		</error>
	</begin>"
}

```

The filter should be:

```auto
filter {
   mutate { gsub => ["message", "\s\s+", ""] }

  json {
    source => "message"
  }
  
  xml {
    source => "xmlRoot"
    target => "xmlFormatted"
  }
	 
}

```

Result:

```auto
{
         "message" => "{\"json\" : \"valueJson\",\"xmlRoot\" : \"<?xml version=\\\"1.0\\\" encoding=\\\"UTF-8\\\"?><begin><error><a>zeffzefzef</a></error></begin>\"}\r",
            "json" => "valueJson",
         "xmlRoot" => "<?xml version=\"1.0\" encoding=\"UTF-8\"?><begin><error><a>zeffzefzef</a></error></begin>",
    "xmlFormatted" => {
        "error" => [
            [0] {
                "a" => [
                    [0] "zeffzefzef"
                ]
            }
        ]
    }
}

```

---

<div class="post-metadata">

**Author:** ![martel](https://avatars.discourse-cdn.com/v4/letter/m/b77776/32.png) [@martel](https://discuss.elastic.co/u/martel)\
**Post date:** [February 11, 2024, 8:09am UTC](https://discuss.elastic.co/t/xml-into-json-value/352933/6 "2024-02-11T08:09:09Z")

</div>

thank you, I will try tomorrow at work, and return here for result.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2024, 8:09am UTC](https://discuss.elastic.co/t/xml-into-json-value/352933/7 "2024-03-10T08:09:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
