SmartQueryTools

Convert NDJSON to XML Online

Convert NDJSON files to XML directly in your browser. Download a structured XML document with one element per row — no upload required.

About converting NDJSON to XML

NDJSON to XML is typically needed at a boundary, when event records produced by a modern service have to be handed to an older consumer: a legacy reporting tool, a batch job with an XML import, or a partner feed that only accepts XML. The converter writes a <data> root with one <row> element per input line and one child element per key.

Log keys often break XML naming rules, so they are rewritten. Elasticsearch and Beats use @timestamp, which becomes <_timestamp>. A flat dotted key such as http.status_code becomes <http_status_code>, and hyphens are replaced too, even though XML allows them. If two keys clean up to the same name, both elements appear with it, so rename such keys first with Rename Columns.

All values are written as element text with no type information, and null becomes an empty element. Nested log context, such as a host or error object, is not expanded into child elements; it is written as JSON text inside one element. Flatten NDJSON first so host.name becomes its own <host_name> element. Unlike NDJSON, the result is one document with a single root, so new events cannot simply be appended to the end.

Worked example

A small sample file, converted with the default settings.

Input (NDJSON)

{"ts":"2026-03-02T14:05:11.042Z","level":"info","service":"checkout","status":200,"latency_ms":41.7,"user_id":"u_1842"}
{"ts":"2026-03-02T14:05:12.310Z","level":"error","service":"checkout","status":502,"latency_ms":3012.4,"user_id":null}
{"ts":"2026-03-02T14:05:12.877Z","level":"info","service":"search","status":200,"latency_ms":12.9,"user_id":"u_0077"}
{"ts":"2026-03-02T14:05:14.105Z","level":"warn","service":"search","status":429,"latency_ms":0.8,"user_id":"u_1842"}

Output (XML)

<?xml version="1.0" encoding="UTF-8"?>
<data>
  <row>
    <ts>2026-03-02T14:05:11.042Z</ts>
    <level>info</level>
    <service>checkout</service>
    <status>200</status>
    <latency_ms>41.7</latency_ms>
    <user_id>u_1842</user_id>
  </row>
  <row>
    <ts>2026-03-02T14:05:12.310Z</ts>
    <level>error</level>
    <service>checkout</service>
    <status>502</status>
    <latency_ms>3012.4</latency_ms>
    <user_id></user_id>
  </row>
  <row>
    <ts>2026-03-02T14:05:12.877Z</ts>
    <level>info</level>
    <service>search</service>
    <status>200</status>
    <latency_ms>12.9</latency_ms>
    <user_id>u_0077</user_id>
  </row>
  <row>
    <ts>2026-03-02T14:05:14.105Z</ts>
    <level>warn</level>
    <service>search</service>
    <status>429</status>
    <latency_ms>0.8</latency_ms>
    <user_id>u_1842</user_id>
  </row>
</data>

What changes when you convert NDJSON to XML

  • Each input line becomes one <row> inside the <data> root, after an XML declaration.
  • Keys become child elements in column order: <ts>, <level>, <service>, <status>, <latency_ms> and <user_id>.
  • The error line has an empty <user_id></user_id> because its value was null.
  • Numbers and timestamps are written as plain text, for example <latency_ms>3012.4</latency_ms>.
  • Keys such as @timestamp or event-id are rewritten as _timestamp and event_id.

Your file is processed locally in your browser and is never uploaded. The free limit is 50 MB per file; larger files work if your device has the memory for them.

Frequently Asked Questions

What happens to the @timestamp field?

The @ is not allowed in an element name, so it is replaced with an underscore and the element is <_timestamp>. Rename the key before converting if the receiver expects a different name.

Can the output be validated against an XSD?

No schema is generated. The structure is regular, with every <row> holding the same children in the same order, so a simple XSD is easy to write. Treat every element as a string, because the XML carries no types.

Can I append new events to the XML file later?

Not by adding lines to the end, as you would with NDJSON. New <row> elements must go before the closing </data> tag. If the log keeps growing, keep NDJSON as the source and regenerate the XML when needed.

Related Tools