---
title: "External actions"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/chapter-patterndb/patterndb-triggers-actions/patterndb-actions-external/"
last_modified: "2023-07-15T16:57:02+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# External actions

To perform an external action when a message is triggered, for example, to send the message in an email, you have to route the generated messages to an external application using the `program()` destination.

## Example: Sending triggered messages to external applications

The following sample configuration selects the triggered messages and sends them to an external script.

1. Set a field in the triggered message that is easy to identify and filter. For example:

   ```xml
       <values>
           <value name="MESSAGE">A log message from ${HOST} matched rule number $.classifier.rule_id</value>
           <value name="TRIGGER">yes</value>
       </values>
   ```
2. Create a destination that will process the triggered messages.

   ```shell
       destination d_triggers {
           program("/bin/myscript"; );
       };
   ```
3. Create a filter that selects the triggered messages from the internal source.

   ```shell
       filter f_triggers {
           match("yes" value ("TRIGGER") type(string));
       };
   ```
4. Create a logpath that selects the triggered messages from the internal source and sends them to the script:

   ```shell
       log { source(s_local); filter(f_triggers); destination(d_triggers); };
   ```
5. Create a script that will actually process the generated messages, for example:

   ```shell
       #!/usr/bin/perl
       while (<>) {
           # body of the script to send emails, snmp traps, and so on
       }
   ```

Last modified July 15, 2023: [Patterndb chapter formatting fixes (f7dfdaa0)](https://github.com/axoflow/axosyslog-core-docs/commit/f7dfdaa0fa045e2ae66345dc5a1c70a179726476)
