# XML log file with multiple opening/closing tags

**URL:** <https://discuss.elastic.co/t/xml-log-file-with-multiple-opening-closing-tags/187089>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 24, 2019, 9:12am UTC](https://discuss.elastic.co/t/xml-log-file-with-multiple-opening-closing-tags/187089 "2019-06-24T09:12:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![moltubakk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moltubakk/32/48626_2.png) [@moltubakk](https://discuss.elastic.co/u/moltubakk)\
**Post date:** [June 24, 2019, 9:12am UTC](https://discuss.elastic.co/t/xml-log-file-with-multiple-opening-closing-tags/187089/1 "2019-06-24T09:12:22Z")

</div>

I'm trying to use Filebeat to ship a number of xml log files that follow a quite simple request/response pattern. I thought this would be easy, but as a newcomer to the ELK stack I really need some help!

Except from the opening / closing tags, the logs have commands from a "mos device" and responses from a nom application. Messages go both ways, so there will also be commands from the 'nom' application to the 'mos device'. The logs look like this:

```
<mosLog Device="SOFIE1.XPRO.MOS" Time="24.06.2019 08:00:36">
<mosCommand Command="heartbeat" Time="24.06.2019 08:00:36" Port="10541" IP="160.67.166.72">
<mos>(....)</mos>
</mosCommand>
<nomResponse Command="heartbeat" Time="24.06.2019 08:00:36" Port="10541" IP="160.67.166.72">
<mos>(....)</mos>
</nomResponse>
</mosLog>

```

In most cases the request and response will have the same timestamp.  
For messages initiated from the 'nom' application, there are "nomCommand"/"mosResponse" tags.

I've tried various solutions, but none of my patterns/flush\_patterns have been able to match the opening/closing tags properly.

Any bright ideas?

---

<div class="post-metadata">

**Author:** ![sjabiulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sjabiulla/32/48429_2.png) [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Post date:** [June 25, 2019, 7:51am UTC](https://discuss.elastic.co/t/xml-log-file-with-multiple-opening-closing-tags/187089/2 "2019-06-25T07:51:48Z")

</div>

Have you tried the [xml filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-xml.html) in Logstash

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2019, 7:52am UTC](https://discuss.elastic.co/t/xml-log-file-with-multiple-opening-closing-tags/187089/3 "2019-07-23T07:52:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
