---
title: "Element: patterns"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/chapter-patterndb/reference-parsers-pattern-databases/reference-patterndb-schemes/patterndb-scheme-patterns/"
last_modified: "2026-09-23T16:42:00+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# Element: patterns

## Location

/[patterndb](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/chapter-patterndb/reference-parsers-pattern-databases/reference-patterndb-schemes/patterndb-scheme-patterndb/index.md)/[ruleset](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/chapter-patterndb/reference-parsers-pattern-databases/reference-patterndb-schemes/patterndb-scheme-ruleset/index.md)/*patterns*

## Description

A container element. A `<patterns>` element may contain any number of `<pattern>` elements.

## Attributes

N/A

## Children

- *pattern*: The name of the application — syslog-ng matches this value to the ${PROGRAM} header of the syslog message to find the rulesets applicable to the syslog message.

  Specifying multiple patterns is useful if two or more applications have different names (that is, different ${PROGRAM} fields), but otherwise send identical log messages.

  It is not necessary to use multiple patterns if only the end of the ${PROGRAM} fields is different, use only the beginning of the ${PROGRAM} field as the `pattern`. For example, the Postfix email server sends messages using different process names, but all of them begin with the `postfix` string.

  You can also use parsers in the program pattern if needed, and use the parsed results later. For example: `<pattern>postfix\@ESTRING:.postfix.component:[@</pattern>`

  > **Note:**
  > If the `<pattern>` element of a ruleset is not specified, AxoSyslog will use this ruleset as a fallback ruleset: it will apply the ruleset to messages that have an empty PROGRAM header, or if none of the program patterns matched the PROGRAM header of the incoming message.

## Example

```shell
   <patterns>
        <pattern>firstapplication</pattern>
        <pattern>otherapplication</pattern>
    </patterns>
```

Using parsers in the program pattern:

```shell
   <pattern>postfix\@ESTRING:.postfix.component:[@</pattern>
```

Last modified September 23, 2026: [Formatting fixes (4b066aca)](https://github.com/axoflow/axosyslog-core-docs/commit/4b066aca197deb5a17c7eb1a56bfae5f8b983172)
