---
title: "parser: Parse and segment structured messages"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/"
description: "Extract name-value pairs from message content with parser drivers for JSON, XML, CSV, key=value, regexp, vendor-specific formats, and pattern databases."
last_modified: "2026-10-01T14:05:08+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# parser: Parse and segment structured messages

Extract name-value pairs from message content with parser drivers for JSON, XML, CSV, key=value, regexp, vendor-specific formats, and pattern databases.

> **FilterX or classic filters, parsers, and rewrite rules?:**
> [FilterX](https://axoflow.com/docs/axosyslog-core/4.28/filterx/index.md) replaces filters, parsers, and rewrite rules with a single typed language that can also handle nested JSON and other complex data. You don’t have to migrate: the classic blocks keep working, and you can use both in the same log path. To convert your existing configuration, see [Update filters to FilterX](https://axoflow.com/docs/axosyslog-core/4.28/filterx/update-filters/index.md).

The filters and default macros of AxoSyslog work well on the headers and metainformation of the log messages, but are rather limited when processing the content of the messages. Parsers can segment the content of the messages into name-value pairs, and these names can be used as user-defined macros. Subsequent filtering or other type of processing of the message can use these custom macros to refer to parts of the message. Parsers are global objects most often used together with filters and rewrite rules.

The AxoSyslog application provides the following possibilities to parse the messages, or parts of the messages, as shown on the following list. There are several built-in parsers for application-specific logs.

Note that by default, AxoSyslog parses every message as a syslog message. To disable parsing the message as a syslog message, use the `flags(no-parse)` option of the source. To explicitly parse a message as a syslog message, use the `syslog` parser. For details, see [Parsing syslog messages](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-syslog/index.md).

---

[Apache access log parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/apache-access-log-parser/index.md)

[Check Point Log Exporter parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-checkpoint/index.md)

[Cisco parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/cisco-parser/index.md)

[Parsing messages with comma-separated and similar values](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/csv-parser/index.md)

[Parsing dates and timestamps](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/date-parser/index.md)

[db-parser: Process message content with a pattern database (patterndb)](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/chapter-patterndb/index.md)

[Parsing enterprise-wide message model (EWMM) messages](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-ewmm/index.md)

[Fortigate parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-fortigate/index.md)

[group-lines parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-group-lines/index.md)

[iptables parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-iptables/index.md)

[JSON parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/json-parser/index.md)

[Parsing key=value pairs](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/key-value-parser/index.md)

[Linux audit parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/linux-audit-parser/index.md)

[MariaDB parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-mariadb-audit/index.md)

[metrics-probe](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/metrics-probe/index.md)

[Netskope parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-netskope/index.md)

[Parse OpenTelemetry messages](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/opentelemetry/index.md)

[panos-parser(): parsing PAN-OS log messages](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/panos-parser/index.md)

[PostgreSQL csvlog](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/postgresql-csvlog-parser/index.md)

[Python parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/python-parser/index.md)

[Regular expression (regexp) parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-regexp/index.md)

[Structured data (SDATA) parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/sdata-parser/index.md)

[Sudo parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-sudo/index.md)

[Parsing syslog messages](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-syslog/index.md)

[Parsing tags](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-tags/index.md)

[Websense parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-websense/index.md)

[Windows XML Event Log (EVTX) parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/windows-eventlog-xml-parser/index.md)

[XML parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/xml-parser/index.md)

Last modified October 1, 2026: [Move filterx chapter higher and link it from classical pages (4a7e94c3)](https://github.com/axoflow/axosyslog-core-docs/commit/4a7e94c3b1f2b935d1aa686abff2c9ee95b863bd)
