# XML parsing using logstash

**URL:** <https://discuss.elastic.co/t/xml-parsing-using-logstash/154811>\
**Category:** Logstash\
**Created:** [October 31, 2018, 10:26am UTC](https://discuss.elastic.co/t/xml-parsing-using-logstash/154811 "2018-10-31T10:26:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ramanna\_hk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramanna_hk/32/52522_2.png) [@ramanna\_hk](https://discuss.elastic.co/u/ramanna_hk)\
**Post date:** [October 31, 2018, 10:26am UTC](https://discuss.elastic.co/t/xml-parsing-using-logstash/154811/1 "2018-10-31T10:26:41Z")

</div>

Hi,

I am working on Nessus logs ex: [`https://gist.github.com/najmisyahir/7a1d2c17257ced61257e3033cd55d090`](https://gist.github.com/najmisyahir/7a1d2c17257ced61257e3033cd55d090)

But i am getting results in array for each fields, please help me to convert to json records.

FYI: i am using logstash 6.0.1 on ubuntu 16

logstash.conf -

```
input {
  file {
    path => "/sampledata/Basic_Scan_Cluster_y7zzst.nessus"
    sincedb_path => "/dev/null"
    start_position => "beginning"
    codec => multiline {
      pattern => "<Report |</NessusClientData_v2>"
      auto_flush_interval => 1
      negate => "true"
      what => "previous"
      max_lines => 1000000000
      max_bytes => "50 MiB"

    }
      tags => "nessus"
      type => "nessus"
  }
}

filter {
  ##interpret the message as XML
    if [type] == "nessus" {
        xml {
            source => "message"
            store_xml => "false"
            force_array => "false"
            
            xpath => ["/Report/ReportHost/@name", host_ip]
            xpath => ["/Report/ReportHost/ReportItem/@pluginName", plugin_name]
            xpath => ["/Report/ReportHost/ReportItem/@pluginID", plugin_id]
            xpath => ["/Report/ReportHost/ReportItem/@severity", risk_score]
            xpath => ["/Report/ReportHost/ReportItem/@port", port]
            xpath => ["/Report/ReportHost/ReportItem/@svc_name", svc_name]
            xpath => ["/Report/ReportHost/ReportItem/@protocol", protocol]
            xpath => ["/Report/ReportHost/ReportItem/@pluginFamily", plugin_family]
            xpath => ["/Report/ReportHost/ReportItem/description/text()", description]
            xpath => ["/Report/ReportHost/ReportItem/risk_factor/text()", risk_factor]
            xpath => ["/Report/ReportHost/ReportItem/see_also/text()", see_also]
            xpath => ["/Report/ReportHost/ReportItem/solution/text()", solution]
            xpath => ["/Report/ReportHost/ReportItem/synopsis/text()", synopsis]
            xpath => ["/Report/ReportHost/ReportItem/plugin_output/text()", plugin_output]
            xpath => ["/Report/ReportHost/HostProperties/tag[@name='HOST_START']/text()", report_host_start]
            xpath => ["/Report/ReportHost/HostProperties/tag[@name='HOST_END']/text()", report_host_end]
        }
        mutate {
          remove_field => ["message"]
          convert => {
              "risk_score" => "integer"
          }
        }

        date {
            match => ["report_host_start", "EEE MMM dd HH:mm:ss yyyy"]
            target => "report_host_start"
            locale => "en_US"
        }
        date {
            match => ["report_host_end", "EEE MMM dd HH:mm:ss yyyy"]
            target => "report_host_end"
            locale => "en_US"
        }
 
    }
}

output {
     elasticsearch { 
        hosts => ["localhost:9200"]
        index => "nessus-data-%{+YYYY.MM.dd}"
      }
      stdout { codec => rubydebug }
}
```

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [October 31, 2018, 10:47am UTC](https://discuss.elastic.co/t/xml-parsing-using-logstash/154811/2 "2018-10-31T10:47:59Z")

</div>

This might help: [Split ES event](https://discuss.elastic.co/t/split-es-event/154152/9?u=jenni)

---

<div class="post-metadata">

**Author:** ![ramanna\_hk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramanna_hk/32/52522_2.png) [@ramanna\_hk](https://discuss.elastic.co/u/ramanna_hk)\
**Post date:** [November 1, 2018, 6:30am UTC](https://discuss.elastic.co/t/xml-parsing-using-logstash/154811/3 "2018-11-01T06:30:18Z")

</div>

Thanks @Jenni, i did it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2018, 6:30am UTC](https://discuss.elastic.co/t/xml-parsing-using-logstash/154811/4 "2018-11-29T06:30:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
