---
title: "Optimizing regular expressions"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-manipulating-messages/regular-expressions/optimizing-regular-expressions/"
last_modified: "2023-07-02T20:37:04+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# Optimizing regular expressions

The `host()`, `match()`, and `program()` filter functions and some other objects accept regular expressions as parameters. But evaluating general regular expressions puts a high load on the CPU, which can cause problems when the message traffic is very high. Often the regular expression can be replaced with simple filter functions and logical operators. Using simple filters and logical operators, the same effect can be achieved at a much lower CPU load.

## Example: Optimizing regular expressions in filters

Suppose you need a filter that matches the following error message logged by the `xntpd` NTP daemon:

```shell
   xntpd[1567]: time error -1159.777379 is too large (set clock manually);
```

The following filter uses regular expressions and matches every instance and variant of this message.

```shell
   filter f_demo_regexp {
        program("demo_program") and
        match("time error .* is too large .* set clock manually");
    };
```

Segmenting the `match()` part of this filter into separate `match()` functions greatly improves the performance of the filter.

```shell
   filter f_demo_optimized_regexp {
        program("demo_program") and
        match("time error") and
        match("is too large") and
        match("set clock manually");
    };
```

Last modified July 2, 2023: [Change highlight mode of code examples (2f8a9593)](https://github.com/axoflow/axosyslog-core-docs/commit/2f8a95937c6498193e7168ce8b0dc831e9f0f8ad)
