# Xml parser with xpath giving wrong result in xml filter plugin

**URL:** <https://discuss.elastic.co/t/xml-parser-with-xpath-giving-wrong-result-in-xml-filter-plugin/97666>\
**Category:** Logstash\
**Created:** [August 19, 2017, 7:05pm UTC](https://discuss.elastic.co/t/xml-parser-with-xpath-giving-wrong-result-in-xml-filter-plugin/97666 "2017-08-19T19:05:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [August 19, 2017, 7:05pm UTC](https://discuss.elastic.co/t/xml-parser-with-xpath-giving-wrong-result-in-xml-filter-plugin/97666/1 "2017-08-19T19:05:07Z")

</div>

Hi All

i am having a xml filter, which looks like this

```
 xml {
          source => "message"
          target => "message_parsed"
          add_tag => ["xml_parsed"]
          remove_namespaces => true
		  store_xml => true
		  force_array => true
          xpath => [
            "/table/row/number/text()","number"
            ]
     }

```

Here i am getting only 1 record. I am expecting 5 records  
Under the column "number" i am getting value as comma seperated  
123,124,125,126,127

My expectation as 5 different events

```
**Number**
123
124
125
126
127

```

I have tried split filter but no luck. I think there can be better solution for this

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 20, 2017, 6:29pm UTC](https://discuss.elastic.co/t/xml-parser-with-xpath-giving-wrong-result-in-xml-filter-plugin/97666/2 "2017-08-20T18:29:58Z")

</div>

Please give an example input document. Post it as preformatted text so the XML doesn't get mangled.

---

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [August 21, 2017, 6:13am UTC](https://discuss.elastic.co/t/xml-parser-with-xpath-giving-wrong-result-in-xml-filter-plugin/97666/3 "2017-08-21T06:13:20Z")

</div>

Hi Here is the input XML, below is the block of 1 record.  
Like this have 2000 records with ..........

```
<S:Envelope xmlns:S="http://schemas.xmlsoap.org/soap/envelope/">
   <S:Body>
      <ns0:advancedSearchResponse xmlns:ns0="http://xmlns.xyz.com/Objects/V1">
         <response>
            <messageId xsi:nil="true" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"/>
            <messageName xsi:nil="true" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"/>
            <statusCode>SUCCESS</statusCode>
            <table>
               <tableIdentifier>
                  <classId xsi:nil="true" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"/>
                  <className xsi:nil="true" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"/>
                  <objectId>6151127</objectId>
                  <objectName xsi:nil="true" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"/>
                  <tableId>-102</tableId>
                  <tableName xsi:nil="true" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"/>
                  <tableDisplayName xsi:nil="true" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"/>
               </tableIdentifier>
               <row rowId="1">
                  <objectReferentId>
                     <classId>2468022</classId>
                     <className>BondWire</className>
                     <classDisplayName xsi:nil="true" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"/>
                     <objectId>6118882</objectId>
                     <objectName xsi:nil="true" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"/>
                     <objectVersion xsi:nil="true" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"/>
                     <version xsi:nil="true" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"/>
                  </objectReferentId>
                  <additionalRowInfo xsi:nil="true" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"/>
                  <number attributeId="1001" xsi:type="xs:string" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">22</number>
                  <Type attributeId="1081" xsi:type="common:ListEntryType" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:common="http://xmlns.xyz.com/Objects/Core/Common/V1">
                     <listName xsi:nil="true"/>
                     <selection>
                        <id>2468022</id>
                        <apiName>BondWire</apiName>
                        <value>Bond Wire</value>
                     </selection>
                  </Type>
                  <description attributeId="1002" xsi:type="xs:string" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">Lifecycle Phase Testing Part, Testing Comma, OKay</description>
                  <phase attributeId="1084" xsi:type="common:ListEntryType" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:common="http://xmlns.xyz.com/Objects/Core/Common/V1">
                     <listName xsi:nil="true"/>
                     <selection>
                        <id>2481963</id>
                        <apiName>ACTIVE_PHASE</apiName>
                        <value>Active Phase</value>
                     </selection>
                  </phase>
               </row>
            </table>
         </response>
      </ns0:advancedSearchResponse>
   </S:Body>
</S:Envelope>

```

Here is my xml filter

```
 xml {
          source => "message"
          target => "message_parsed"
          add_tag => ["xml_parsed"]
          remove_namespaces => true
		  store_xml => true
		  force_array => true
          xpath => [
            "/Envelope/Body/advancedSearchResponse/response/table/row/number/text()","number",
			"/Envelope/Body/advancedSearchResponse/response/table/row/type/selection/value/text()","type",
			"/Envelope/Body/advancedSearchResponse/response/table/row/description/text()","description",
			"/Envelope/Body/advancedSearchResponse/response/table/row/phase/selection/value/text()","phase"
			
            ]
     }

```

Output is my ES

The response which i get is

```
number : 22,23,24,25,....
type: Bond Wire,abc, def, ghi....
description: desc1, desc2......
phase: phase1,phase2.... etc.

```

I need to split this in multiple events. Which is not working currently.  
Any idea how to do this?

---

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [August 21, 2017, 5:54pm UTC](https://discuss.elastic.co/t/xml-parser-with-xpath-giving-wrong-result-in-xml-filter-plugin/97666/4 "2017-08-21T17:54:04Z")

</div>

Hi @magnusbaeck

Any suggestion as how can i achieve this

Thanks

---

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [August 24, 2017, 2:16am UTC](https://discuss.elastic.co/t/xml-parser-with-xpath-giving-wrong-result-in-xml-filter-plugin/97666/5 "2017-08-24T02:16:45Z")

</div>

Seeking suggestions on this. I feel this is very common problem. Many might have faced similar situation.  
Please provide suggestions

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 24, 2017, 2:33pm UTC](https://discuss.elastic.co/t/xml-parser-with-xpath-giving-wrong-result-in-xml-filter-plugin/97666/6 "2017-08-24T14:33:07Z")

</div>

See this ongoing thread:

> [@Use of Split Filter for more than 1 fields, it is possible](https://discuss.elastic.co/t/use-of-split-filter-for-more-than-1-fields-it-is-possible/97687):
>
> Hi All my output is like this Field1 : A,B,C,D Field2: E,F,G,H Field3: W,X,Y,Z Field4: Q,R,S,T Now i am using split filter in conf file split {field =\> "[Field1]"} split {field =\> "[Field2]"} split {field =\> "[Field3]"} split {field =\> "[Field4]"} My Expected result is Field1 Field2 Field3 Field4 A E W Q B F X R C G Y S D H Z T The conf file keeps running forever and doesn't create index

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2017, 2:33pm UTC](https://discuss.elastic.co/t/xml-parser-with-xpath-giving-wrong-result-in-xml-filter-plugin/97666/7 "2017-09-21T14:33:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
