---
title: "Parsing enterprise-wide message model (EWMM) messages"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/parser-ewmm/"
last_modified: "2026-08-05T13:56:51+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# Parsing enterprise-wide message model (EWMM) messages

The `ewmm-parser()` can be used to parse messages sent by another AxoSyslog host using the enterprise-wide message model (EWMM) format. Available in version 3.16 and later. Note that usually you do not have to use this parser directly, because the [default-network-drivers() source](https://axoflow.com/docs/axosyslog-core/4.28/chapter-sources/source-default-network-drivers/index.md) automatically parses such messages.

## Prerequisites

Install the `axosyslog-scl` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md). On [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md), the SCL files are part of the `axosyslog` base package.

Your configuration must also contain `@include "scl.conf"`, which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

```shell
@include "scl.conf"
```

## Declaration:

```shell
   parser parser_name {
        ewmm-parser();
    };
```

Last modified August 5, 2026: [Adds required packages to parser pages (d1286917)](https://github.com/axoflow/axosyslog-core-docs/commit/d12869175ade2e2652453d62a823a7b95a4c84b6)
