Try it free

DPL XML Documents

  • Latest Dynatrace
  • Reference

Overview

The XML, XML_PLAIN, and XML_VERBOSE matchers parse XML documents into structured records, each producing a different level of detail. XML adapts its output based on content (including attributes and text), XML_PLAIN discards attributes for a simpler structure, and XML_VERBOSE always uses a fixed, fully explicit structure regardless of content. The following comparison uses this input:

<book id="b1">
<title>DPL Guide</title>
<author>Alice</author>
</book>

Use the following expression to parse the XML input into a record:

XML:xml
{
"book": {
"@id": "b1",
"title": "DPL Guide",
"author": "Alice"
}
}

Use the following expression to parse the XML input into a record:

XML_PLAIN:xml_plain
{
"book": {
"title": "DPL Guide",
"author": "Alice"
}
}

Use the following expression to parse the XML input into a record:

XML_VERBOSE:xml_verbose
{
"book": {
"@id": "b1",
"title": { "#text": "DPL Guide" },
"author": { "#text": "Alice" }
}
}
See how to use in DQL
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")
| parse input, "XML:xml"
| parse input, "XML_PLAIN:xml_plain"
| parse input, "XML_VERBOSE:xml_verbose"

XML

The XML matcher parses XML documents, creating a structure that adapts to the content of the XML document.

The following mapping rules apply when using the XML matcher:

  • Elements are represented as fields.
  • Child elements form nested fields.
  • Attributes are mapped to nested fields by adding @ as a prefix in the field name. For example, attribute <... attr="..."> becomes field @attr.
  • In the presence of attributes or child elements, the text content of elements is represented as a nested #text field.
  • The #text field becomes an array when mixing child elements (or comments) with multiple text content parts.
  • For elements without attributes or child elements, the text content becomes the value of the corresponding field.
  • Elements that occur multiple times are mapped to arrays.
  • Namespace prefixes are included in the field name. For example, element <prefix:element> becomes field prefix:element.
  • XML declarations (version and encoding attributes) are discarded.
  • Attribute values and text content are represented as strings.
  • Comments are discarded.

Alternatively, you can use the XML_PLAIN or XML_VERBOSE matchers with a fixed output structure.

For example, given the following input:

<book id="b1">
<title>DPL Guide</title>
<author>Alice</author>
</book>

Use the following expression to parse the value:

XML:xml

The matcher keeps the id attribute as an @id field:

{
"book": {
"@id": "b1",
"title": "DPL Guide",
"author": "Alice"
}
}
See how to use in DQL
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")
| parse input, "XML:xml"

Configuration

Specify configuration parameters in parentheses after the matcher name: XML(param=value):xml.

ParameterTypeDescription

rootTag

string

Name of the XML element from which to parse content. The first occurrence is selected if multiple such elements exist. Default: the whole XML document is parsed.

excludeRoot

boolean

When true, excludes the root element from the output. Default: false.

ignoreNamespace

boolean

When true, removes namespace prefixes in the output. Default: false.

maxlen

long

Maximum byte size of the XML document to parse. Allows parsing large XML documents that exceed the default size. Default: 128000. Maximum: 512000000.

charset

string

Character set name, enclosed in single or double quotes (for example, charset="ISO-8859-1").

locale

string

IETF BCP 47 language tag, enclosed in single or double quotes. For more information, see the list. Default: English.

Returns

The data type of the extracted value is record.

Basic examples

Example 1: Parse the first element with a given tag name

The rootTag parameter starts parsing at the named element, selecting it out of the document. Precede the matcher with LD so it can advance to that element, and include any namespace prefix in the name.

Given the following input:

<library>
<book id="b1">
<title>DPL Guide</title>
</book>
<magazine id="m1">
<title>DQL Weekly</title>
</magazine>
</library>

Use the following pattern to select the magazine element:

LD XML(rootTag="magazine"):xml
{
"magazine": {
"@id": "m1",
"title": "DQL Weekly"
}
}
See how to use in DQL
data record(input = "<library><book id=\"b1\"><title>DPL Guide</title></book><magazine id=\"m1\"><title>DQL Weekly</title></magazine></library>")
| parse input, "LD XML(rootTag=\"magazine\"):xml"
Example 2: Parse the contents of the root element using excludeRoot

The excludeRoot parameter drops the top-level element and returns its contents directly.

Given the following input:

<book id="b1">
<title>DPL Guide</title>
<author>Alice</author>
</book>

Use the following pattern to drop the book root and return its contents:

XML(excludeRoot=true):xml
{
"@id": "b1",
"title": "DPL Guide",
"author": "Alice"
}
See how to use in DQL
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")
| parse input, "XML(excludeRoot=true):xml"
Example 3: Parse field names without namespace prefixes using ignoreNamespace

The ignoreNamespace parameter removes namespace prefixes from the field names in the output.

Given the following input:

<bk:book xmlns:bk="http://example.com/books">
<bk:title>DPL Guide</bk:title>
</bk:book>

Use the following pattern to remove the bk: namespace prefix:

XML(ignoreNamespace=true):xml
{
"book": {
"title": "DPL Guide"
}
}
See how to use in DQL
data record(input = "<bk:book xmlns:bk=\"http://example.com/books\"><bk:title>DPL Guide</bk:title></bk:book>")
| parse input, "XML(ignoreNamespace=true):xml"

Practical examples

Example 1: Parse a messages document

Given the following input:

<?xml version="1.0" encoding="UTF-8"?>
<messages xmlns:xhtml="http://www.w3.org/1999/xhtml">
<thread id="1">
<topic>XML Parsing</topic>
<!-- comment -->
<message id="101">
<sender>Alice</sender>
<content type="plain">&lt;b&gt;text&lt;/b&gt;</content>
</message>
<message id="102">
<sender>Bob</sender>
<content type="plain"><![CDATA[<b>text</b>]]></content>
</message>
<message id="103">
<sender>John</sender>
<content type="xhtml">More <xhtml:b>text</xhtml:b> here.</content>
</message>
<message id="104">
<sender>Mary</sender>
<content type="xhtml">Some <!-- hidden text --> included.</content>
</message>
</thread>
</messages>

Use the following pattern to parse the message thread into a record:

XML:xml
{
"messages":{
"@xmlns:xhtml":"http://www.w3.org/1999/xhtml",
"thread":{
"@id":"1",
"topic":"XML Parsing",
"message":[
{
"@id":"101",
"sender":"Alice",
"content":{"@type":"plain", "#text":"<b>text</b>"}
},
{
"@id":"102",
"sender":"Bob",
"content":{"@type":"plain", "#text":"<b>text</b>"}
},
{
"@id":"103",
"sender":"John",
"content":{"@type":"xhtml", "xhtml:b":"text", "#text":["More "," here."]}
},
{
"@id":"104",
"sender":"Mary",
"content":{"@type":"xhtml", "#text":["Some "," included."]}
}
]
}
}
}
See how to use in DQL
data record(input = "<?xml version=\"1.0\" encoding=\"UTF-8\"?><messages xmlns:xhtml=\"http://www.w3.org/1999/xhtml\"><thread id=\"1\"><topic>XML Parsing</topic><!-- comment --><message id=\"101\"><sender>Alice</sender><content type=\"plain\">&lt;b&gt;text&lt;/b&gt;</content></message><message id=\"102\"><sender>Bob</sender><content type=\"plain\"><![CDATA[<b>text</b>]]></content></message><message id=\"103\"><sender>John</sender><content type=\"xhtml\">More <xhtml:b>text</xhtml:b> here.</content></message><message id=\"104\"><sender>Mary</sender><content type=\"xhtml\">Some <!-- hidden text --> included.</content></message></thread></messages>")
| parse input, "XML:xml"
Example 2: Parse XML embedded in a log line

Log records rarely contain only XML. The XML is usually preceded by a timestamp, log level, or other text. Use LD (or another matcher) to advance to the start of the document, then apply the XML matcher.

Avoid placing a DATA matcher directly between an anchoring string literal and the XML matcher: DATA consumes at least one character, so the parser starts inside the document and captures only a fragment. Anchor with a literal and let XML begin at the <.

Given the following input:

2025-06-17 21:24:08 INFO OrderService - outbound - <order id="A-1001"><status>SHIPPED</status></order>

Use the following pattern to skip the log prefix and parse the trailing XML:

LD 'outbound - ' XML:xml
{
"order": {
"@id": "A-1001",
"status": "SHIPPED"
}
}
See how to use in DQL
data record(input = "2025-06-17 21:24:08 INFO OrderService - outbound - <order id=\"A-1001\"><status>SHIPPED</status></order>")
| parse input, "LD 'outbound - ' XML:xml"

XML_PLAIN

With XML_PLAIN, you get a streamlined version of the XML data. The matcher discards attributes of XML elements. It can be helpful for cases where this information is unnecessary since it reduces the output structure's complexity, making it easier to work with the parsed data.

XML_PLAIN uses the following mapping rules:

  • Elements are represented as fields.
  • Child elements form nested fields.
  • Attributes of elements are discarded.
  • The text content of elements becomes the value of the corresponding field.
  • Text content mixed with child elements is discarded.
  • Elements that occur multiple times are mapped to arrays.
  • Namespace prefixes are included in the field name. For example, element <prefix:element> becomes field prefix:element.
  • XML declarations (version and encoding attributes) are discarded.
  • Text content is represented as strings.
  • Comments are discarded.

For example, given the following input:

<book id="b1">
<title>DPL Guide</title>
<author>Alice</author>
</book>

Use the following expression to parse the value:

XML_PLAIN:xml_plain

The matcher discards the id attribute:

{
"book": {
"title": "DPL Guide",
"author": "Alice"
}
}
See how to use in DQL
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")
| parse input, "XML_PLAIN:xml_plain"

Configuration

Specify configuration parameters in parentheses after the matcher name: XML_PLAIN(param=value):xml_plain.

ParameterTypeDescription

rootTag

string

Name of the XML element from which to parse content. The first occurrence is selected if multiple such elements exist. Default: the whole XML document is parsed.

excludeRoot

boolean

When true, excludes the root element from the output. Default: false.

ignoreNamespace

boolean

When true, removes namespace prefixes in the output. Default: false.

maxlen

long

Maximum byte size of the XML document to parse. Allows parsing large XML documents that exceed the default size. Default: 128000. Maximum: 512000000.

charset

string

Character set name, enclosed in single or double quotes (for example, charset="ISO-8859-1").

locale

string

IETF BCP 47 language tag, enclosed in single or double quotes. For more information, see the list. Default: English.

Returns

The data type of the extracted value is record.

Basic examples

Example 1: Parse the first element with a given tag name

The rootTag parameter starts parsing at the named element, selecting it out of the document. Precede the matcher with LD so it can advance to that element, and include any namespace prefix in the name.

Given the following input:

<library>
<book id="b1">
<title>DPL Guide</title>
</book>
<magazine id="m1">
<title>DQL Weekly</title>
</magazine>
</library>

Use the following pattern to select the magazine element:

LD XML_PLAIN(rootTag="magazine"):xml_plain
{
"magazine": {
"title": "DQL Weekly"
}
}
See how to use in DQL
data record(input = "<library><book id=\"b1\"><title>DPL Guide</title></book><magazine id=\"m1\"><title>DQL Weekly</title></magazine></library>")
| parse input, "LD XML_PLAIN(rootTag=\"magazine\"):xml_plain"
Example 2: Parse the contents of the root element using excludeRoot

The excludeRoot parameter drops the top-level element and returns its contents directly.

Given the following input:

<book id="b1">
<title>DPL Guide</title>
<author>Alice</author>
</book>

Use the following pattern to drop the book root and return its contents:

XML_PLAIN(excludeRoot=true):xml_plain
{
"title": "DPL Guide",
"author": "Alice"
}
See how to use in DQL
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")
| parse input, "XML_PLAIN(excludeRoot=true):xml_plain"
Example 3: Parse field names without namespace prefixes using ignoreNamespace

The ignoreNamespace parameter removes namespace prefixes from the field names in the output.

Given the following input:

<bk:book xmlns:bk="http://example.com/books">
<bk:title>DPL Guide</bk:title>
</bk:book>

Use the following pattern to remove the bk: namespace prefix:

XML_PLAIN(ignoreNamespace=true):xml_plain
{
"book": {
"title": "DPL Guide"
}
}
See how to use in DQL
data record(input = "<bk:book xmlns:bk=\"http://example.com/books\"><bk:title>DPL Guide</bk:title></bk:book>")
| parse input, "XML_PLAIN(ignoreNamespace=true):xml_plain"

Practical example

Example: Parse a messages document

Given the following input:

<?xml version="1.0" encoding="UTF-8"?>
<messages xmlns:xhtml="http://www.w3.org/1999/xhtml">
<thread id="1">
<topic>XML Parsing</topic>
<!-- comment -->
<message id="101">
<sender>Alice</sender>
<content type="plain">&lt;b&gt;text&lt;/b&gt;</content>
</message>
<message id="102">
<sender>Bob</sender>
<content type="plain"><![CDATA[<b>text</b>]]></content>
</message>
<message id="103">
<sender>John</sender>
<content type="xhtml">More <xhtml:b>text</xhtml:b> here.</content>
</message>
<message id="104">
<sender>Mary</sender>
<content type="xhtml">Some <!-- hidden text --> included.</content>
</message>
</thread>
</messages>

Use the following pattern to parse the message thread into a simplified record:

XML_PLAIN:xml_plain
{
"messages":{
"thread":{
"topic":"XML Parsing",
"message":[
{
"sender":"Alice",
"content":"<b>text</b>"
},
{
"sender":"Bob",
"content":"<b>text</b>"
},
{
"sender":"John",
"content":{"xhtml:b":"text"}
},
{
"sender":"Mary",
"content":"Some included."
}
]
}
}
}
See how to use in DQL
data record(input = "<?xml version=\"1.0\" encoding=\"UTF-8\"?><messages xmlns:xhtml=\"http://www.w3.org/1999/xhtml\"><thread id=\"1\"><topic>XML Parsing</topic><!-- comment --><message id=\"101\"><sender>Alice</sender><content type=\"plain\">&lt;b&gt;text&lt;/b&gt;</content></message><message id=\"102\"><sender>Bob</sender><content type=\"plain\"><![CDATA[<b>text</b>]]></content></message><message id=\"103\"><sender>John</sender><content type=\"xhtml\">More <xhtml:b>text</xhtml:b> here.</content></message><message id=\"104\"><sender>Mary</sender><content type=\"xhtml\">Some <!-- hidden text --> included.</content></message></thread></messages>")
| parse input, "XML_PLAIN:xml_plain"

XML_VERBOSE

You receive the most detailed and comprehensive data structure when parsing XML documents using the XML_VERBOSE matcher. In contrast to the XML matcher, the XML_VERBOSE matcher creates an output structure that is fixed and does not depend on the presence of element attributes or child elements.

XML_VERBOSE uses the following mapping rules:

  • Elements are represented as fields.
  • Child elements form nested fields.
  • Attributes are mapped to nested fields by adding @ as a prefix in the field name. For example, attribute <... attr="..."> becomes field @attr.
  • The text content of elements is represented as a nested #text field.
  • The #text field becomes an array when mixing child elements (or comments) with multiple text content parts.
  • Elements that occur multiple times are mapped to arrays.
  • Namespace prefixes are included in the field name. For example, element <prefix:element> becomes field prefix:element.
  • XML declarations (version and encoding attributes) are mapped to fields at the root element level.
  • Attribute values and text content are represented as strings.
  • Comments are discarded.

For example, given the following input:

<book id="b1">
<title>DPL Guide</title>
<author>Alice</author>
</book>

Use the following expression to parse the value:

XML_VERBOSE:xml_verbose

The matcher keeps the id attribute and wraps each text value in a #text field:

{
"book": {
"@id": "b1",
"title": { "#text": "DPL Guide" },
"author": { "#text": "Alice" }
}
}
See how to use in DQL
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")
| parse input, "XML_VERBOSE:xml_verbose"

Configuration

Specify configuration parameters in parentheses after the matcher name: XML_VERBOSE(param=value):xml_verbose.

ParameterTypeDescription

rootTag

string

Name of the XML element from which to parse content. The first occurrence is selected if multiple such elements exist. Default: the whole XML document is parsed.

excludeRoot

boolean

When true, excludes the root element from the output. Default: false.

ignoreNamespace

boolean

When true, removes namespace prefixes in the output. Default: false.

maxlen

long

Maximum byte size of the XML document to parse. Allows parsing large XML documents that exceed the default size. Default: 128000. Maximum: 512000000.

charset

string

Character set name, enclosed in single or double quotes (for example, charset="ISO-8859-1").

locale

string

IETF BCP 47 language tag, enclosed in single or double quotes. For more information, see the list. Default: English.

Returns

The data type of the extracted value is record.

Basic examples

Example 1: Parse the first element with a given tag name

The rootTag parameter starts parsing at the named element, selecting it out of the document. Precede the matcher with LD so it can advance to that element, and include any namespace prefix in the name.

Given the following input:

<library>
<book id="b1">
<title>DPL Guide</title>
</book>
<magazine id="m1">
<title>DQL Weekly</title>
</magazine>
</library>

Use the following pattern to select the magazine element:

LD XML_VERBOSE(rootTag="magazine"):xml_verbose
{
"magazine": {
"@id": "m1",
"title": { "#text": "DQL Weekly" }
}
}
See how to use in DQL
data record(input = "<library><book id=\"b1\"><title>DPL Guide</title></book><magazine id=\"m1\"><title>DQL Weekly</title></magazine></library>")
| parse input, "LD XML_VERBOSE(rootTag=\"magazine\"):xml_verbose"
Example 2: Parse the contents of the root element using excludeRoot

The excludeRoot parameter drops the top-level element and returns its contents directly.

Given the following input:

<book id="b1">
<title>DPL Guide</title>
<author>Alice</author>
</book>

Use the following pattern to drop the book root and return its contents:

XML_VERBOSE(excludeRoot=true):xml_verbose
{
"@id": "b1",
"title": { "#text": "DPL Guide" },
"author": { "#text": "Alice" }
}
See how to use in DQL
data record(input = "<book id=\"b1\"><title>DPL Guide</title><author>Alice</author></book>")
| parse input, "XML_VERBOSE(excludeRoot=true):xml_verbose"
Example 3: Parse field names without namespace prefixes using ignoreNamespace

The ignoreNamespace parameter removes namespace prefixes from the field names in the output.

Given the following input:

<bk:book xmlns:bk="http://example.com/books">
<bk:title>DPL Guide</bk:title>
</bk:book>

Use the following pattern to remove the bk: namespace prefix:

XML_VERBOSE(ignoreNamespace=true):xml_verbose
{
"book": {
"title": { "#text": "DPL Guide" }
}
}
See how to use in DQL
data record(input = "<bk:book xmlns:bk=\"http://example.com/books\"><bk:title>DPL Guide</bk:title></bk:book>")
| parse input, "XML_VERBOSE(ignoreNamespace=true):xml_verbose"

Practical example

Example: Parse a messages document

Given the following input:

<?xml version="1.0" encoding="UTF-8"?>
<messages xmlns:xhtml="http://www.w3.org/1999/xhtml">
<thread id="1">
<topic>XML Parsing</topic>
<!-- comment -->
<message id="101">
<sender>Alice</sender>
<content type="plain">&lt;b&gt;text&lt;/b&gt;</content>
</message>
<message id="102">
<sender>Bob</sender>
<content type="plain"><![CDATA[<b>text</b>]]></content>
</message>
<message id="103">
<sender>John</sender>
<content type="xhtml">More <xhtml:b>text</xhtml:b> here.</content>
</message>
<message id="104">
<sender>Mary</sender>
<content type="xhtml">Some <!-- hidden text --> included.</content>
</message>
</thread>
</messages>

Use the following pattern to parse the message thread into a fully explicit record:

XML_VERBOSE:xml_verbose
{
"@version":"1.0",
"@encoding":"UTF-8",
"messages":{
"@xmlns:xhtml":"http://www.w3.org/1999/xhtml",
"thread":{
"@id":"1",
"topic":{"#text":"XML Parsing"},
"message":[
{
"@id":"101",
"sender":{"#text":"Alice"},
"content":{"@type":"plain", "#text":"<b>text</b>"}
},
{
"@id":"102",
"sender":{"#text":"Bob"},
"content":{"@type":"plain", "#text":"<b>text</b>"
}
},
{
"@id":"103",
"sender":{"#text":"John"},
"content":{"@type":"xhtml", "xhtml:b":{"#text":"text"}, "#text":["More "," here."]}
},
{
"@id":"104",
"sender":{"#text":"Mary"},
"content":{"@type":"xhtml", "#text":["Some "," included."]}
}
]
}
}
}
See how to use in DQL
data record(input = "<?xml version=\"1.0\" encoding=\"UTF-8\"?><messages xmlns:xhtml=\"http://www.w3.org/1999/xhtml\"><thread id=\"1\"><topic>XML Parsing</topic><!-- comment --><message id=\"101\"><sender>Alice</sender><content type=\"plain\">&lt;b&gt;text&lt;/b&gt;</content></message><message id=\"102\"><sender>Bob</sender><content type=\"plain\"><![CDATA[<b>text</b>]]></content></message><message id=\"103\"><sender>John</sender><content type=\"xhtml\">More <xhtml:b>text</xhtml:b> here.</content></message><message id=\"104\"><sender>Mary</sender><content type=\"xhtml\">Some <!-- hidden text --> included.</content></message></thread></messages>")
| parse input, "XML_VERBOSE:xml_verbose"
Related tags
Dynatrace Platform