Modify messages using rewrite rules
FilterX or classic filters, parsers, and rewrite rules?
FilterX replaces filters, parsers, and rewrite rules with a single typed language that can also handle nested JSON and other complex data. You don’t have to migrate: the classic blocks keep working, and you can use both in the same log path. To convert your existing configuration, see Update filters to FilterX.
The AxoSyslog application can rewrite parts of the messages using rewrite rules. Rewrite rules are global objects similar to parsers and filters and can be used in log paths. The AxoSyslog application has two methods to rewrite parts of the log messages: substituting (setting) a part of the message to a fix value, and a general search-and-replace mode.
- Substitution completely replaces a specific part of the message that is referenced using a built-in or user-defined macro.
- General rewriting searches for a string in the entire message (or only a part of the message specified by a macro) and replaces it with another string. Optionally, this replacement string can be a template that contains macros.
Rewriting messages is often used in conjunction with message parsing parser: Parse and segment structured messages.
Rewrite rules are similar to filters: they must be defined in the syslog-ng.conf configuration file and used in the log statement. You can also define the rewrite rule inline in the log path.
Note
The order of filters, rewriting rules, and parsers in the log statement is important, as they are processed sequentially.
Last modified October 1, 2026: Move filterx chapter higher and link it from classical pages (4a7e94c3)