Match macros ($1, $2, ... $255) are temporary variables. You can use them for general purposes when operating with list-like items. For example, the match() filter stores capture group results in match variables when the store-matches flag is set, or the JSON parser produces match variables if the parsed JSON data is an array.
It is possible to set match variables in a single operation with the set-matches() rewrite function. set-matches() uses AxoSyslog list expressions to set $1, $2, ... $255, so it can be considered as a conversion function between AxoSyslog lists and match variables.
$* macro, which can be further manipulated using list template functions, or turned into a list in type-aware destinations.
unset-matches() rewrite rule.
Declaration
rewrite <name_of_the_rule> {
set-matches("<list-expression or list-based template function>");
};
Example for the set-matches() rewrite function
In the following two examples, $1, $2, and $3 will be set to foo, bar, and baz, respectively.
Using strings:
rewrite {
set-matches("foo,bar,baz");
};
Using a list template function:
rewrite {
set-matches("$(explode ':' 'foo:bar:baz')");
};
unset-matches()
The unset-matches() rewrite rule clears every match variable, that is, it resets $1, $2, ... $255 to empty. Use it when you want to make sure that match variables left over from an earlier filter, parser, or rewrite rule do not leak into later parts of the log path.
rewrite <name_of_the_rule> {
unset-matches();
};
Example for the unset-matches() rewrite function
The following log path sets three match variables, then clears them again, so $1, $2, and $3 are empty when the message reaches the destination.
log {
source(s_local);
rewrite { set-matches("foo,bar,baz"); };
rewrite { unset-matches(); };
destination(d_local);
};
Options
Both set-matches() and unset-matches() have the following option.
<!-- This file is under the copyright of Axoflow, and licensed under Apache License 2.0, except for using the Axoflow and AxoSyslog trademarks. -->
condition()
| Type: | filter expression |
| Default: | N/A |
Description: Applies the rewrite rule only to the messages that match the specified filter expression. Messages that don’t match the filter pass through the rule unmodified, and continue to the next element of the log path. You can use any filter expression here, and you can reference an existing filter with the filter() function. For details, see Conditional rewrites.