# Replace message parts

To replace a part of the log message, you have to:

  * define a string or regular expression to find the text to replace
  * define a string to replace the original text (macros can be used as well)
  * select the field of the message that the rewrite rule should process



Substitution rules can operate on any soft macros, for example, MESSAGE, PROGRAM, or any user-defined macros created using parsers. You can also rewrite the structured-data fields of messages complying to the RFC5424 (IETF-syslog) message format.

Note Hard macros cannot be modified. For details, see [Hard versus soft macros](../../../docs/axosyslog-core/4.26/chapter-manipulating-messages/customizing-message-format/macros-hard-vs-soft/index.md). 

See also the equivalent FilterX function, [`regexp_subst()`](../../../docs/axosyslog-core/4.26/filterx/function-reference/index.md#regexp-subst), or [`str_replace()`](../../../docs/axosyslog-core/4.26/filterx/function-reference/index.md#str-replace) for literal strings.

Substitution rules use the following syntax:

## Declaration

Terminal window
```
    rewrite <name_of_the_rule> {
        subst(
            "<string or regular expression to find>",
            "<replacement string>", value(<field name>), flags()
        );
    };
```

The `type()` and `flags()` options are optional. The `type()` specifies the type of regular expression to use, while the `flags()` are the flags of the regular expressions. For details on regular expressions, see [Regular expressions](../../../docs/axosyslog-core/4.26/chapter-manipulating-messages/regular-expressions/index.md).

A single substitution rule can include multiple substitutions that are applied sequentially to the message. Note that rewriting rules must be included in the log statement to have any effect.

Note For case-insensitive searches, add the `flags(ignore-case)` option. To replace every occurrence of the string, add `flags(global)` option. Note that the `store-matches` flag is automatically enabled in rewrite rules. 

## Example: Using substitution rules

The following example replaces the `IP` in the text of the message with the string `IP-Address`.

Terminal window
```
    rewrite r_rewrite_subst{
        subst("IP", "IP-Address", value("MESSAGE"));
    };
```

To replace every occurrence, use:

Terminal window
```
    rewrite r_rewrite_subst{
        subst("IP", "IP-Address", value("MESSAGE"), flags("global"));
    };
```

Multiple substitution rules are applied sequentially. The following rules replace the first occurrence of the string `IP` with the string `IP-Addresses`.

Terminal window
```
    rewrite r_rewrite_subst{
        subst("IP", "IP-Address", value("MESSAGE"));
        subst("Address", "Addresses", value("MESSAGE"));
    };
```

### Example: Anonymizing IP addresses

The following example replaces every IPv4 address in the MESSAGE part with its SHA-1 hash:

Terminal window
```
       rewrite pseudonymize_ip_addresses_in_message {subst ("((([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])[.]){3}([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5]))", "$(sha1 $0)", value("MESSAGE"));};
```

## Options

The `subst()` rewrite rule has the following options.

## condition()

|   
---|---  
Type: | filter expression  
Default: | N/A  
  
_Description:_ Applies the rewrite rule only to the messages that match the specified filter expression. Messages that don’t match the filter pass through the rule unmodified, and continue to the next element of the log path. You can use any filter expression here, and you can reference an existing filter with the `filter()` function. For details, see [Conditional rewrites](../../../docs/axosyslog-core/4.26/chapter-manipulating-messages/modifying-messages/conditional-rewrite/index.md).

## flags()

|   
---|---  
Type: | list of flags  
Default: | empty set  
  
_Description:_ The flags of the regular expression. The available flags depend on the [`type()`](../../../docs/axosyslog-core/4.26/chapter-manipulating-messages/modifying-messages/rewrite-replace/index.md#type) of the regular expression. For case-insensitive searches, use `flags(ignore-case)`. To replace every occurrence of the pattern, use `flags(global)`. Note that the `store-matches` flag is automatically enabled in rewrite rules. For details, see [Regular expressions](../../../docs/axosyslog-core/4.26/chapter-manipulating-messages/regular-expressions/index.md).

## internal()

|   
---|---  
Accepted values: | `yes`, `no`  
Default: | `no`  
  
_Description:_ Marks this pipeline element as internal. Elements marked as `internal()` are treated as an implementation detail, so for example statistics of the given pipe are available only on higher stats level. This option is mainly useful for developers or when writing SCL blocks and integrations.

## type()

|   
---|---  
Type: | `pcre`, `string`, `glob`  
Default: | `pcre`  
  
_Description:_ Sets how AxoSyslog interprets the search pattern: as a Perl Compatible Regular Expression (`pcre`, used by default), a literal string search (`string`), or a glob pattern without regular expression support (`glob`). For details, see [Options of regular expressions](../../../docs/axosyslog-core/4.26/chapter-manipulating-messages/regular-expressions/reference-regexp-types/index.md).

## value()

|   
---|---  
Type: | name of a message field  
Default: | `MESSAGE`  
  
_Description:_ Selects the field of the message that the rewrite rule modifies. If you don’t set it, the rule operates on the `MESSAGE` field.

Write the name of the field without the `$` prefix, for example, `value("HOST")`, not `value("$HOST")`. The `$` prefix is only needed in templates, and AxoSyslog logs a warning if you use it here. You cannot set a hard macro in the `value()` option, AxoSyslog rejects the configuration with an error.

Last modified August 10, 2026: [Sync rewrite rule options with the source (d33662b7)](<https://github.com/axoflow/axosyslog-core-docs/commit/d33662b7e6212a930666d724aa0ba2f88d4ba4ae>)