This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Parsing enterprise-wide message model (EWMM) messages

The ewmm-parser() can be used to parse messages sent by another AxoSyslog host using the enterprise-wide message model (EWMM) format. Available in version 3.16 and later. Note that usually you do not have to use this parser directly, because the default-network-drivers() source automatically parses such messages.

Prerequisites

Install the axosyslog-scl package on Debian/Ubuntu. On RHEL and compatible distributions, the SCL files are part of the axosyslog base package.

Your configuration must also contain @include "scl.conf", which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with an unexpected LL_IDENTIFIER error.

Terminal window
@include "scl.conf"

Declaration:

Terminal window
   parser parser_name {
        ewmm-parser();
    };