# Xpath Functions in Logstash

**URL:** <https://discuss.elastic.co/t/xpath-functions-in-logstash/295119>\
**Category:** Logstash\
**Created:** [January 22, 2022, 3:15pm UTC](https://discuss.elastic.co/t/xpath-functions-in-logstash/295119 "2022-01-22T15:15:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tim\_Mobley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_mobley/32/94741_2.png) [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Post date:** [January 22, 2022, 3:15pm UTC](https://discuss.elastic.co/t/xpath-functions-in-logstash/295119/1 "2022-01-22T15:15:06Z")

</div>

I am needing to use [xpath functions](https://docs.oracle.com/cd/E68885_01/doc.731/e68892/dev_xpath_functions.htm#OSMDR767) like `string-join()` and `concat()` to extract what I need from my XML file, however whenever I use these functions I get the following warning in my logstash-plain.log:

> [2022-01-21T20:45:34,777][WARN][logstash.filters.xml][scap-results]  
> ....XML Parse Error {:exception=\>"string-join(/cdf:Benchmark/cdf:TestResult/cdf:rule-result[./cdf:result = 'fail']/(concat(@idref, ' - ', @severity, ' - ', @weight, ' - ', ./cdf:result/text())), codepoints-to-string(10)): javax.xml.transform.TransformerException: Could not find function: string-join", :source=\>"message"....

Elastic's [xpath filter plugin documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-xml.html#plugins-filters-xml-xpath_resources) mentions xpath functions, so it must be possible, however they do not give any examples. I should say I have no problem with the xpath expressions and both my expressions and functions work fine in [online xpath testers](https://www.freeformatter.com/xpath-tester.html).

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 22, 2022, 4:53pm UTC](https://discuss.elastic.co/t/xpath-functions-in-logstash/295119/2 "2022-01-22T16:53:05Z")

</div>

As I understand it, javax.xml implements XPath 1.0, and string-join was introduced in XPath 2.0, so it is not available.

Not sure about concat, it was introduced in 1.x but I do not know if javax.xml supports it.

---

<div class="post-metadata">

**Author:** ![Tim\_Mobley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_mobley/32/94741_2.png) [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Post date:** [January 22, 2022, 11:42pm UTC](https://discuss.elastic.co/t/xpath-functions-in-logstash/295119/3 "2022-01-22T23:42:10Z")

</div>

That's the answer to why `string-join` failed, so thank you! But I still haven't found an example where someone is using a xpath (1.0) function in Logstash. So if you or anyone has an example, that'd be great. I removed the 2.0 functions and just used concat() and still got an XML parse failure:

> [2022-01-22T18:01:42,343][WARN][logstash.filters.xml][scap-results][7c534c31269189a290afb01983b864ba4a5201d44b94d816ddebe62db807efc0] XML Parse Error {:exception=\>"/cdf:Benchmark/cdf:TestResult/cdf:rule-result/(concat(@idref, ' - ', @severity, ' - ', @weight)): javax.xml.transform.TransformerException: A location step was expected following the '/' or '//' token."

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 23, 2022, 12:54am UTC](https://discuss.elastic.co/t/xpath-functions-in-logstash/295119/4 "2022-01-23T00:54:40Z")

</div>

It took me ages to experiment with this, and I still cannot get it to work with namespaces but for this XML

```
<Benchmark id="Windows-XP-Desktop-800-68-1" resolved="1" xml:lang="en" xmlns:cdf="http://checklists.nist.gov/xccdf/1.1">
<TestResult id="Windows-XP-SP-800-68-1" end-time="2007-09-26T05:30:48" test-system="cpe:/a:securitycompany:productname:1.0">
    <rule-result idref="MinimumPasswordAge" time="2007-09-26T05:30:49"/>
</TestResult>
</Benchmark>

```

the filter

```
    xml {
        force_array => false
        store_xml => false
        source => "message"
        xpath => { "concat(/Benchmark/TestResult/@id, ' - ', /Benchmark/TestResult/rule-result/@idref)" => "foo" }
        remove_field => ["message", "event"]
    }

```

will produce

```
       "foo" => "Windows-XP-SP-800-68-1 - MinimumPasswordAge",
```

---

<div class="post-metadata">

**Author:** ![Tim\_Mobley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_mobley/32/94741_2.png) [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Post date:** [January 23, 2022, 6:43pm UTC](https://discuss.elastic.co/t/xpath-functions-in-logstash/295119/5 "2022-01-23T18:43:31Z")

</div>

I got it to work with namespaces, but it seems the key is that the function has to be at the beginning of the xpath (as in your example). It doesn't appear to work _inside_ a path. Anyway, thank you once again for your time and help! At least now I know what is and isn't possible.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2022, 6:44pm UTC](https://discuss.elastic.co/t/xpath-functions-in-logstash/295119/6 "2022-02-20T18:44:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
