# How send XML file form Kismet into GrayLog with NXLog

**URL:** <https://community.graylog.org/t/how-send-xml-file-form-kismet-into-graylog-with-nxlog/5399>\
**Category:** Graylog Central (peer support)\
**Tags:** sidecar, nxlog, multi-linenx\
**Created:** [May 30, 2018, 12:22pm UTC](https://community.graylog.org/t/how-send-xml-file-form-kismet-into-graylog-with-nxlog/5399 "2018-05-30T12:22:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![haker146](https://avatars.discourse-cdn.com/v4/letter/h/977dab/32.png) [@haker146](https://community.graylog.org/u/haker146)\
**Post date:** [May 30, 2018, 12:22pm UTC](https://community.graylog.org/t/how-send-xml-file-form-kismet-into-graylog-with-nxlog/5399/1 "2018-05-30T12:22:21Z")

</div>

Hi, I write to you with a problem. For some time I’ve been trying to configure NXlog so that it parses the xml file that I get from the Kismet tool. I want graylog to show me all the information about the found Wi-fi networks. Based on the guides on the Internet, I carried out the Nxlog configuration. Here I put the nxlog.conf file

```
 ## This is a sample configuration file. See the nxlog reference manual about the
## configuration options. It should be installed locally under
## /usr/share/doc/nxlog-ce/ and is also available online at
## http://nxlog.org/docs

########################################
# Global directives #
########################################
User nxlog
Group nxlog

LogFile /var/log/nxlog/nxlog.log
LogLevel INFO

########################################
# Modules #
########################################
<Extension _gelf>
Module xm_gelf
</Extension>

<Extension multiline>
Module xm_multiline
HeaderLine /^<event>/
EndLine /^</event>/
</Extension>

<Extension xmlparser>
Module xm_xml
</Extension>

<Extension json>
Module xm_json
</Extension>

<Input in>
Module im_file
File "/root/Magisterka/wifiids/test.xml"
SavePos FALSE
ReadFromLast FALSE
InputType multiline
<Exec>
  # Discard everything that doesn't seem to be an xml event   
  if $raw_event !~ /^<event>/ drop();
  # Parse the xml event
  parse_xml();

  # Rewrite some fields 
  $EventTime = parsedate($timestamp);
  delete($timestamp);
  delete($EventReceivedTime);

  # Convert to JSON
  to_json();
</Exec>
</Input>

<Output out>
Module om_udp
Host 192.168.75.138
Port 12201
OutputType GELF
</Output>

<Route 1>
Path in => out
</Route>

```

Unfortunately, in this configuration an error message appears when you try to add an entry to the gray log and start it. Below is the configuration of the graylog input

 ![Graylog%20input](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/d/d5bf83e2e8480b150babc9cb90e4aaf561ed4c62.png)

I am using grayloga as a virtual machine, the system on which the xml file is located is installed on a separate virtual machine.  
Virtual machine with graylog IP: 192.168.75.138  
Machine with an xml file IP: 192.168.75.139

---

<div class="post-metadata">

**Author:** ![haker146](https://avatars.discourse-cdn.com/v4/letter/h/977dab/32.png) [@haker146](https://community.graylog.org/u/haker146)\
**Post date:** [May 30, 2018, 1:16pm UTC](https://community.graylog.org/t/how-send-xml-file-form-kismet-into-graylog-with-nxlog/5399/2 "2018-05-30T13:16:36Z")

</div>

Graylog displays the following message:

 ![b%C5%82%C4%85d](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/4/4edc0aa00bee718a7466b15559b11f39d7c798b6.jpg)

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [May 30, 2018, 1:18pm UTC](https://community.graylog.org/t/how-send-xml-file-form-kismet-into-graylog-with-nxlog/5399/3 "2018-05-30T13:18:14Z")

</div>

Check the logs of your Graylog and Elasticsearch nodes.  
➡ [http://docs.graylog.org/en/2.4/pages/configuration/file\_location.html](http://docs.graylog.org/en/2.4/pages/configuration/file_location.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [June 13, 2018, 1:18pm UTC](https://community.graylog.org/t/how-send-xml-file-form-kismet-into-graylog-with-nxlog/5399/4 "2018-06-13T13:18:18Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
