---
title: "Element: rule"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/chapter-patterndb/reference-parsers-pattern-databases/reference-patterndb-schemes/patterndb-scheme-rule/"
last_modified: "2026-09-23T16:42:00+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# Element: rule

## Location

/[patterndb](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/chapter-patterndb/reference-parsers-pattern-databases/reference-patterndb-schemes/patterndb-scheme-patterndb/index.md)/[ruleset](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/chapter-patterndb/reference-parsers-pattern-databases/reference-patterndb-schemes/patterndb-scheme-ruleset/index.md)/[rules](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/chapter-patterndb/reference-parsers-pattern-databases/reference-patterndb-schemes/patterndb-scheme-rules/index.md)/*rule*

## Description

An element containing message patterns and how a message that matches these patterns is classified.

> **Note:**
>
> If the following characters appear in the message, they must be escaped in the rule as follows:
>
> - `@`: Use @@, for example, `user@@example.com`
> - *<*: Use `\&lt;`
> - *>*: Use `\&gt;`
> - &: Use `\&amp;`

The `<rules>` element may contain any number of `<rule>` elements.

## Attributes

- *provider*: The provider of the rule. This is used to distinguish between who supplied the rule, that is, if it has been created by Axoflow, or added to the XML by a local user.
- *id*: The globally unique ID of the rule.
- *class*: The class of the rule — this class is assigned to the messages matching a pattern of this rule.

## Children

- *patterns*

## Example

```shell
   <rule provider='example' id='f57196aa-75fd-11dd-9bba-001e6806451b' class='violation'>
```

The following example specifies attributes for correlating messages as well. For details on correlating messages, see [Correlating log messages using pattern databases](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/chapter-patterndb/configuring-pattern-databases/patterndb-correlation/index.md).

```shell
   <rule provider='example' id='f57196aa-75fd-11dd-9bba-001e6806451b' class='violation' context-id='same-session' context-scope='process' context-timeout='360'>
```

Last modified September 23, 2026: [Formatting fixes (4b066aca)](https://github.com/axoflow/axosyslog-core-docs/commit/4b066aca197deb5a17c7eb1a56bfae5f8b983172)
