The XML, XML_PLAIN, and XML_VERBOSE matchers parse XML documents into structured records, each producing a different level of detail. XML adapts its output based on content (including attributes and text), XML_PLAIN discards attributes for a simpler structure, and XML_VERBOSE always uses a fixed, fully explicit structure regardless of content. The following comparison uses this input:
<book id="b1"><title>DPL Guide</title><author>Alice</author></book>
Use the following expression to parse the XML input into a record:
XML:xml
{"book": {"@id": "b1","title": "DPL Guide","author": "Alice"}}
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")| parse input, "XML:xml"| parse input, "XML_PLAIN:xml_plain"| parse input, "XML_VERBOSE:xml_verbose"
The XML matcher parses XML documents, creating a structure that adapts to the content of the XML document.
The following mapping rules apply when using the XML matcher:
@ as a prefix in the field name.
For example, attribute <... attr="..."> becomes field @attr.#text field.#text field becomes an array when mixing child elements (or comments) with multiple text content parts.<prefix:element> becomes field prefix:element.Alternatively, you can use the XML_PLAIN or XML_VERBOSE matchers with a fixed output structure.
For example, given the following input:
<book id="b1"><title>DPL Guide</title><author>Alice</author></book>
Use the following expression to parse the value:
XML:xml
The matcher keeps the id attribute as an @id field:
{"book": {"@id": "b1","title": "DPL Guide","author": "Alice"}}
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")| parse input, "XML:xml"
Specify configuration parameters in parentheses after the matcher name: XML(param=value):xml.
| Parameter | Type | Description |
|---|---|---|
|
| Name of the XML element from which to parse content. The first occurrence is selected if multiple such elements exist. Default: the whole XML document is parsed. |
|
| When |
|
| When |
|
| Maximum byte size of the XML document to parse. Allows parsing large XML documents that exceed the default size. Default: |
|
| Character set name, enclosed in single or double quotes (for example, |
|
| IETF BCP 47 language tag, enclosed in single or double quotes. For more information, see the list. Default: English. |
The data type of the extracted value is record.
The rootTag parameter starts parsing at the named element, selecting it out of the document. Precede the matcher with LD so it can advance to that element, and include any namespace prefix in the name.
Given the following input:
<library><book id="b1"><title>DPL Guide</title></book><magazine id="m1"><title>DQL Weekly</title></magazine></library>
Use the following pattern to select the magazine element:
LD XML(rootTag="magazine"):xml
{"magazine": {"@id": "m1","title": "DQL Weekly"}}
data record(input = "<library><book id=\"b1\"><title>DPL Guide</title></book><magazine id=\"m1\"><title>DQL Weekly</title></magazine></library>")| parse input, "LD XML(rootTag=\"magazine\"):xml"
excludeRootThe excludeRoot parameter drops the top-level element and returns its contents directly.
Given the following input:
<book id="b1"><title>DPL Guide</title><author>Alice</author></book>
Use the following pattern to drop the book root and return its contents:
XML(excludeRoot=true):xml
{"@id": "b1","title": "DPL Guide","author": "Alice"}
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")| parse input, "XML(excludeRoot=true):xml"
ignoreNamespaceThe ignoreNamespace parameter removes namespace prefixes from the field names in the output.
Given the following input:
<bk:book xmlns:bk="http://example.com/books"><bk:title>DPL Guide</bk:title></bk:book>
Use the following pattern to remove the bk: namespace prefix:
XML(ignoreNamespace=true):xml
{"book": {"title": "DPL Guide"}}
data record(input = "<bk:book xmlns:bk=\"http://example.com/books\"><bk:title>DPL Guide</bk:title></bk:book>")| parse input, "XML(ignoreNamespace=true):xml"
Given the following input:
<?xml version="1.0" encoding="UTF-8"?><messages xmlns:xhtml="http://www.w3.org/1999/xhtml"><thread id="1"><topic>XML Parsing</topic><!-- comment --><message id="101"><sender>Alice</sender><content type="plain"><b>text</b></content></message><message id="102"><sender>Bob</sender><content type="plain"><![CDATA[<b>text</b>]]></content></message><message id="103"><sender>John</sender><content type="xhtml">More <xhtml:b>text</xhtml:b> here.</content></message><message id="104"><sender>Mary</sender><content type="xhtml">Some <!-- hidden text --> included.</content></message></thread></messages>
Use the following pattern to parse the message thread into a record:
XML:xml
{"messages":{"@xmlns:xhtml":"http://www.w3.org/1999/xhtml","thread":{"@id":"1","topic":"XML Parsing","message":[{"@id":"101","sender":"Alice","content":{"@type":"plain", "#text":"<b>text</b>"}},{"@id":"102","sender":"Bob","content":{"@type":"plain", "#text":"<b>text</b>"}},{"@id":"103","sender":"John","content":{"@type":"xhtml", "xhtml:b":"text", "#text":["More "," here."]}},{"@id":"104","sender":"Mary","content":{"@type":"xhtml", "#text":["Some "," included."]}}]}}}
data record(input = "<?xml version=\"1.0\" encoding=\"UTF-8\"?><messages xmlns:xhtml=\"http://www.w3.org/1999/xhtml\"><thread id=\"1\"><topic>XML Parsing</topic><!-- comment --><message id=\"101\"><sender>Alice</sender><content type=\"plain\"><b>text</b></content></message><message id=\"102\"><sender>Bob</sender><content type=\"plain\"><![CDATA[<b>text</b>]]></content></message><message id=\"103\"><sender>John</sender><content type=\"xhtml\">More <xhtml:b>text</xhtml:b> here.</content></message><message id=\"104\"><sender>Mary</sender><content type=\"xhtml\">Some <!-- hidden text --> included.</content></message></thread></messages>")| parse input, "XML:xml"
Log records rarely contain only XML. The XML is usually preceded by a timestamp, log level, or other text. Use LD (or another matcher) to advance to the start of the document, then apply the XML matcher.
Avoid placing a DATA matcher directly between an anchoring string literal and the XML matcher: DATA consumes at least one character, so the parser starts inside the document and captures only a fragment. Anchor with a literal and let XML begin at the <.
Given the following input:
2025-06-17 21:24:08 INFO OrderService - outbound - <order id="A-1001"><status>SHIPPED</status></order>
Use the following pattern to skip the log prefix and parse the trailing XML:
LD 'outbound - ' XML:xml
{"order": {"@id": "A-1001","status": "SHIPPED"}}
data record(input = "2025-06-17 21:24:08 INFO OrderService - outbound - <order id=\"A-1001\"><status>SHIPPED</status></order>")| parse input, "LD 'outbound - ' XML:xml"
With XML_PLAIN, you get a streamlined version of the XML data. The matcher discards attributes of XML elements. It can be helpful for cases where this information is unnecessary since it reduces the output structure's complexity, making it easier to work with the parsed data.
XML_PLAIN uses the following mapping rules:
<prefix:element> becomes field prefix:element.For example, given the following input:
<book id="b1"><title>DPL Guide</title><author>Alice</author></book>
Use the following expression to parse the value:
XML_PLAIN:xml_plain
The matcher discards the id attribute:
{"book": {"title": "DPL Guide","author": "Alice"}}
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")| parse input, "XML_PLAIN:xml_plain"
Specify configuration parameters in parentheses after the matcher name: XML_PLAIN(param=value):xml_plain.
| Parameter | Type | Description |
|---|---|---|
|
| Name of the XML element from which to parse content. The first occurrence is selected if multiple such elements exist. Default: the whole XML document is parsed. |
|
| When |
|
| When |
|
| Maximum byte size of the XML document to parse. Allows parsing large XML documents that exceed the default size. Default: |
|
| Character set name, enclosed in single or double quotes (for example, |
|
| IETF BCP 47 language tag, enclosed in single or double quotes. For more information, see the list. Default: English. |
The data type of the extracted value is record.
The rootTag parameter starts parsing at the named element, selecting it out of the document. Precede the matcher with LD so it can advance to that element, and include any namespace prefix in the name.
Given the following input:
<library><book id="b1"><title>DPL Guide</title></book><magazine id="m1"><title>DQL Weekly</title></magazine></library>
Use the following pattern to select the magazine element:
LD XML_PLAIN(rootTag="magazine"):xml_plain
{"magazine": {"title": "DQL Weekly"}}
data record(input = "<library><book id=\"b1\"><title>DPL Guide</title></book><magazine id=\"m1\"><title>DQL Weekly</title></magazine></library>")| parse input, "LD XML_PLAIN(rootTag=\"magazine\"):xml_plain"
excludeRootThe excludeRoot parameter drops the top-level element and returns its contents directly.
Given the following input:
<book id="b1"><title>DPL Guide</title><author>Alice</author></book>
Use the following pattern to drop the book root and return its contents:
XML_PLAIN(excludeRoot=true):xml_plain
{"title": "DPL Guide","author": "Alice"}
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")| parse input, "XML_PLAIN(excludeRoot=true):xml_plain"
ignoreNamespaceThe ignoreNamespace parameter removes namespace prefixes from the field names in the output.
Given the following input:
<bk:book xmlns:bk="http://example.com/books"><bk:title>DPL Guide</bk:title></bk:book>
Use the following pattern to remove the bk: namespace prefix:
XML_PLAIN(ignoreNamespace=true):xml_plain
{"book": {"title": "DPL Guide"}}
data record(input = "<bk:book xmlns:bk=\"http://example.com/books\"><bk:title>DPL Guide</bk:title></bk:book>")| parse input, "XML_PLAIN(ignoreNamespace=true):xml_plain"
Given the following input:
<?xml version="1.0" encoding="UTF-8"?><messages xmlns:xhtml="http://www.w3.org/1999/xhtml"><thread id="1"><topic>XML Parsing</topic><!-- comment --><message id="101"><sender>Alice</sender><content type="plain"><b>text</b></content></message><message id="102"><sender>Bob</sender><content type="plain"><![CDATA[<b>text</b>]]></content></message><message id="103"><sender>John</sender><content type="xhtml">More <xhtml:b>text</xhtml:b> here.</content></message><message id="104"><sender>Mary</sender><content type="xhtml">Some <!-- hidden text --> included.</content></message></thread></messages>
Use the following pattern to parse the message thread into a simplified record:
XML_PLAIN:xml_plain
{"messages":{"thread":{"topic":"XML Parsing","message":[{"sender":"Alice","content":"<b>text</b>"},{"sender":"Bob","content":"<b>text</b>"},{"sender":"John","content":{"xhtml:b":"text"}},{"sender":"Mary","content":"Some included."}]}}}
data record(input = "<?xml version=\"1.0\" encoding=\"UTF-8\"?><messages xmlns:xhtml=\"http://www.w3.org/1999/xhtml\"><thread id=\"1\"><topic>XML Parsing</topic><!-- comment --><message id=\"101\"><sender>Alice</sender><content type=\"plain\"><b>text</b></content></message><message id=\"102\"><sender>Bob</sender><content type=\"plain\"><![CDATA[<b>text</b>]]></content></message><message id=\"103\"><sender>John</sender><content type=\"xhtml\">More <xhtml:b>text</xhtml:b> here.</content></message><message id=\"104\"><sender>Mary</sender><content type=\"xhtml\">Some <!-- hidden text --> included.</content></message></thread></messages>")| parse input, "XML_PLAIN:xml_plain"
You receive the most detailed and comprehensive data structure when parsing XML documents using the XML_VERBOSE matcher. In contrast to the XML matcher, the XML_VERBOSE matcher creates an output structure that is fixed and does not depend on the presence of element attributes or child elements.
XML_VERBOSE uses the following mapping rules:
@ as a prefix in the field name.
For example, attribute <... attr="..."> becomes field @attr.#text field.#text field becomes an array when mixing child elements (or comments) with multiple text content parts.<prefix:element> becomes field prefix:element.For example, given the following input:
<book id="b1"><title>DPL Guide</title><author>Alice</author></book>
Use the following expression to parse the value:
XML_VERBOSE:xml_verbose
The matcher keeps the id attribute and wraps each text value in a #text field:
{"book": {"@id": "b1","title": { "#text": "DPL Guide" },"author": { "#text": "Alice" }}}
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")| parse input, "XML_VERBOSE:xml_verbose"
Specify configuration parameters in parentheses after the matcher name: XML_VERBOSE(param=value):xml_verbose.
| Parameter | Type | Description |
|---|---|---|
|
| Name of the XML element from which to parse content. The first occurrence is selected if multiple such elements exist. Default: the whole XML document is parsed. |
|
| When |
|
| When |
|
| Maximum byte size of the XML document to parse. Allows parsing large XML documents that exceed the default size. Default: |
|
| Character set name, enclosed in single or double quotes (for example, |
|
| IETF BCP 47 language tag, enclosed in single or double quotes. For more information, see the list. Default: English. |
The data type of the extracted value is record.
The rootTag parameter starts parsing at the named element, selecting it out of the document. Precede the matcher with LD so it can advance to that element, and include any namespace prefix in the name.
Given the following input:
<library><book id="b1"><title>DPL Guide</title></book><magazine id="m1"><title>DQL Weekly</title></magazine></library>
Use the following pattern to select the magazine element:
LD XML_VERBOSE(rootTag="magazine"):xml_verbose
{"magazine": {"@id": "m1","title": { "#text": "DQL Weekly" }}}
data record(input = "<library><book id=\"b1\"><title>DPL Guide</title></book><magazine id=\"m1\"><title>DQL Weekly</title></magazine></library>")| parse input, "LD XML_VERBOSE(rootTag=\"magazine\"):xml_verbose"
excludeRootThe excludeRoot parameter drops the top-level element and returns its contents directly.
Given the following input:
<book id="b1"><title>DPL Guide</title><author>Alice</author></book>
Use the following pattern to drop the book root and return its contents:
XML_VERBOSE(excludeRoot=true):xml_verbose
{"@id": "b1","title": { "#text": "DPL Guide" },"author": { "#text": "Alice" }}
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")| parse input, "XML_VERBOSE(excludeRoot=true):xml_verbose"
ignoreNamespaceThe ignoreNamespace parameter removes namespace prefixes from the field names in the output.
Given the following input:
<bk:book xmlns:bk="http://example.com/books"><bk:title>DPL Guide</bk:title></bk:book>
Use the following pattern to remove the bk: namespace prefix:
XML_VERBOSE(ignoreNamespace=true):xml_verbose
{"book": {"title": { "#text": "DPL Guide" }}}
data record(input = "<bk:book xmlns:bk=\"http://example.com/books\"><bk:title>DPL Guide</bk:title></bk:book>")| parse input, "XML_VERBOSE(ignoreNamespace=true):xml_verbose"
Given the following input:
<?xml version="1.0" encoding="UTF-8"?><messages xmlns:xhtml="http://www.w3.org/1999/xhtml"><thread id="1"><topic>XML Parsing</topic><!-- comment --><message id="101"><sender>Alice</sender><content type="plain"><b>text</b></content></message><message id="102"><sender>Bob</sender><content type="plain"><![CDATA[<b>text</b>]]></content></message><message id="103"><sender>John</sender><content type="xhtml">More <xhtml:b>text</xhtml:b> here.</content></message><message id="104"><sender>Mary</sender><content type="xhtml">Some <!-- hidden text --> included.</content></message></thread></messages>
Use the following pattern to parse the message thread into a fully explicit record:
XML_VERBOSE:xml_verbose
{"@version":"1.0","@encoding":"UTF-8","messages":{"@xmlns:xhtml":"http://www.w3.org/1999/xhtml","thread":{"@id":"1","topic":{"#text":"XML Parsing"},"message":[{"@id":"101","sender":{"#text":"Alice"},"content":{"@type":"plain", "#text":"<b>text</b>"}},{"@id":"102","sender":{"#text":"Bob"},"content":{"@type":"plain", "#text":"<b>text</b>"}},{"@id":"103","sender":{"#text":"John"},"content":{"@type":"xhtml", "xhtml:b":{"#text":"text"}, "#text":["More "," here."]}},{"@id":"104","sender":{"#text":"Mary"},"content":{"@type":"xhtml", "#text":["Some "," included."]}}]}}}
data record(input = "<?xml version=\"1.0\" encoding=\"UTF-8\"?><messages xmlns:xhtml=\"http://www.w3.org/1999/xhtml\"><thread id=\"1\"><topic>XML Parsing</topic><!-- comment --><message id=\"101\"><sender>Alice</sender><content type=\"plain\"><b>text</b></content></message><message id=\"102\"><sender>Bob</sender><content type=\"plain\"><![CDATA[<b>text</b>]]></content></message><message id=\"103\"><sender>John</sender><content type=\"xhtml\">More <xhtml:b>text</xhtml:b> here.</content></message><message id=\"104\"><sender>Mary</sender><content type=\"xhtml\">Some <!-- hidden text --> included.</content></message></thread></messages>")| parse input, "XML_VERBOSE:xml_verbose"