# XML parsing is failing with REXML::ParseException: Missing end tag

**URL:** <https://discuss.elastic.co/t/xml-parsing-is-failing-with-rexml-missing-end-tag/362462>\
**Category:** Logstash\
**Created:** [July 3, 2024, 12:43pm UTC](https://discuss.elastic.co/t/xml-parsing-is-failing-with-rexml-missing-end-tag/362462 "2024-07-03T12:43:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ayushyadav685](https://avatars.discourse-cdn.com/v4/letter/a/8baadc/32.png) [@ayushyadav685](https://discuss.elastic.co/u/ayushyadav685)\
**Post date:** [July 3, 2024, 12:43pm UTC](https://discuss.elastic.co/t/xml-parsing-is-failing-with-rexml-missing-end-tag/362462/1 "2024-07-03T12:43:15Z")

</div>

Hi All,

I am trying to migrate the XML logs to JSON with Logstash, but the parsing fails due to some unnecessary XML logs. The `<exception>` tag is not needed and I attempted to remove it using `remove_tag`, but it is not working.

Added this in config  
remove\_tag =\> ["exception"]

```auto
<?xml version="1.0" encoding="UTF-8"?>
<logger>
  <log>
    <server>
      <exception name="Address already in use (Bind failed)">
        java.net.BindException: Address already in use (Bind failed)
        java.net.ServerSocket.<init>(ServerSocket.java:237)
      </exception>
    </server>
  </log>
</logger>

```

exception:

`:exception=>#<REXML::ParseException: Missing end tag for 'init' (got 'exception')`

this is the config:

```auto
input {
  file {
    mode => "read"
    path => "log11.xml"
    sincedb_path => "nul"
    start_position => "beginning"
    type => "xml"
    codec => multiline {
      pattern => "^logger>"
      negate => true
      what => "previous"
    }
  }
}

filter {
  xml {
    remove_tag => ["exception"]
    source => "message"
    xpath => []
    target => "xml_value"
  }
  mutate {
    remove_field => [tags, host, message, xml_value]
  }
}

output {
  stdout {
    codec => json
  }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 3, 2024, 1:23pm UTC](https://discuss.elastic.co/t/xml-parsing-is-failing-with-rexml-missing-end-tag/362462/2 "2024-07-03T13:23:55Z")

</div>

> [@ayushyadav685](#):
>
> `java.net.ServerSocket.<init>`

That init "tag" is never terminated. For this specific case you could use

```
 mutate { gsub => ["message", "<init>", "&lt;init&gt;"] }

```

It's going to be a lot of work to generalize that.

To answer your actual question ... remove\_tag will not work. It remove entries from the [tags] field (an array) if the filter successfully parses the XML. However, it will never be applied if there is an XML parse error, and even if it were it would not remove the \<exception\> element.

You can fix this using

```
    mutate { gsub => [ "message", "
", "" ] }
    mutate { gsub => ["message", "<exception .*</exception>", ""] }

```

Yes, that is a literal newline embedded inside the string that the first mutate is trying to match.

Note that once you remove the \<exception\> element there is nothing left in the \<logger\> element so you will end up with

```
 "xml_value" => nil,

```

---

<div class="post-metadata">

**Author:** ![ayushyadav685](https://avatars.discourse-cdn.com/v4/letter/a/8baadc/32.png) [@ayushyadav685](https://discuss.elastic.co/u/ayushyadav685)\
**Post date:** [July 3, 2024, 3:07pm UTC](https://discuss.elastic.co/t/xml-parsing-is-failing-with-rexml-missing-end-tag/362462/3 "2024-07-03T15:07:52Z")

</div>

Thanks @Badger for your input.

`<exception>` is just one of the tags in my XML log file.

I tried replacing `<init>` with an empty string, but it is not working.

Here is my updated Logstash configuration:

```auto
input {
  file {
    mode => "read"
    path => "log11.xml"
    sincedb_path => "nul"
    start_position => "beginning"
    type => "xml"
    codec => multiline {
      pattern => "^logger>"
      negate => true
      what => "previous"
    }
  }
}

filter {
  xml {
    source => "message"
    xpath => []
    target => "xml_value"
  }
  
  mutate {
    gsub => ["message", "<init>", ""]
  }
}

output {
  stdout {
    codec => json
  }
}

```

Even I tried both expressions which you mention  
`mutate { gsub => ["message", "<init>", "&lt;init&gt;"] }`

```auto
mutate { gsub => [ "message", "
", "" ] }
    mutate { gsub => ["message", "<exception .*</exception>", ""] }

```

But still same exception is coming.

`:exception=>#<REXML::ParseException: Missing end tag for 'init' (got 'exception')`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 3, 2024, 4:16pm UTC](https://discuss.elastic.co/t/xml-parsing-is-failing-with-rexml-missing-end-tag/362462/4 "2024-07-03T16:16:18Z")

</div>

The exception is occurring when the xml parser hits the string in the midst of the XML. You need to remove it before trying to parse it.

Move the mutate+gsub to come before the xml filter.
