# XML key:value Extraction

**URL:** <https://discuss.elastic.co/t/xml-key-value-extraction/246182>\
**Category:** Logstash\
**Created:** [August 24, 2020, 8:07pm UTC](https://discuss.elastic.co/t/xml-key-value-extraction/246182 "2020-08-24T20:07:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![teej](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@teej](https://discuss.elastic.co/u/teej)\
**Post date:** [August 24, 2020, 8:07pm UTC](https://discuss.elastic.co/t/xml-key-value-extraction/246182/1 "2020-08-24T20:07:43Z")

</div>

Apologies, I have searched but cannot seem to find a good example on how to extract and then index the remaining data. If this is addressed elsewhere and Ive missed it please direct me there. Being new to logstash and its filtering mechanism I cannot seem to find how to take the following xml file format:

```
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:bclog="http://www.ciglo.com/wcf/log/v1_0" elementFormDefault="unqualified" targetNamespace="http://www.ciglo.com/wcf/log/v1_0" version="1.0">
  <xs:element name="bcLogEntry" type="bclog:bcLogEntry"/>

      <xs:complexType name="bcLogEntry">
        <xs:sequence>
          <xs:element minOccurs="0" name="c_ip" type="xs:string">
            <xs:annotation>
              <xs:documentation><![CDATA[abrigo: c-ip]]></xs:documentation>
            </xs:annotation>
          </xs:element>
          <xs:element minOccurs="0" name="c_port" type="xs:int">
            <xs:annotation>
              <xs:documentation><![CDATA[abrigo: c-port]]></xs:documentation>
            </xs:annotation>
          </xs:element>
          <xs:element minOccurs="0" name="cs_Accept_" type="xs:string">
            <xs:annotation>
              <xs:documentation><![CDATA[abrigo: cs(Accept)]]>

```

and only index the fields as:

name:c\_ip, type:string  
name:c\_port, type:int  
name:cs\_Accept\_" type=string

etc.

I would be grateful for any assistance. Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 24, 2020, 10:31pm UTC](https://discuss.elastic.co/t/xml-key-value-extraction/246182/2 "2020-08-24T22:31:42Z")

</div>

Please edit your post, select the XML (not the whole post) and click on \</\> in the toolbar above the edit pane.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 25, 2020, 3:21pm UTC](https://discuss.elastic.co/t/xml-key-value-extraction/246182/3 "2020-08-25T15:21:33Z")

</div>

Assuming you ingest a complete and valid XML string as a single event, then the following filter

```
    xml { source => "message" target => "[@metadata][theXML]" }
    ruby {
        code => '
            elements = event.get("[@metadata][theXML][complexType][0][sequence][0][element]")
            elements.each { |x|
                event.set(x["name"], x["type"])
            }
        '
    }

```

will get you an event with

```
    "c_port" => "xs:int",
      "c_ip" => "xs:string",
"cs_Accept_" => "xs:string",

```

which is probably not quite what you want, but should give you an idea of how to get there.

---

<div class="post-metadata">

**Author:** ![teej](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@teej](https://discuss.elastic.co/u/teej)\
**Post date:** [August 25, 2020, 4:51pm UTC](https://discuss.elastic.co/t/xml-key-value-extraction/246182/4 "2020-08-25T16:51:59Z")

</div>

Badger,  
That's awesome. Thank you very much. That definitely gave me direction.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2020, 4:52pm UTC](https://discuss.elastic.co/t/xml-key-value-extraction/246182/5 "2020-09-22T16:52:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
