File: //usr/share/doc/rsyslog/html/concepts/multi_ruleset.html
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Multiple Rulesets in rsyslog — rsyslog 8.2006.0 documentation</title>
<link rel="stylesheet" href="../_static/classic.css" type="text/css" />
<link rel="stylesheet" href="../_static/pygments.css" type="text/css" />
<link rel="stylesheet" href="../_static/rsyslog.css" type="text/css" />
<script type="text/javascript">
var DOCUMENTATION_OPTIONS = {
URL_ROOT: '../',
VERSION: '8.2006.0',
COLLAPSE_INDEX: false,
FILE_SUFFIX: '.html',
HAS_SOURCE: true,
SOURCELINK_SUFFIX: '.txt'
};
</script>
<script type="text/javascript" src="../_static/jquery.js"></script>
<script type="text/javascript" src="../_static/underscore.js"></script>
<script type="text/javascript" src="../_static/doctools.js"></script>
<link rel="index" title="Index" href="../genindex.html" />
<link rel="search" title="Search" href="../search.html" />
<link rel="next" title="Legacy Format Samples for Multiple Rulesets" href="../historical/multi_ruleset_legacy_format_samples.html" />
<link rel="prev" title="Message parsers in rsyslog" href="messageparser.html" />
</head>
<body>
<div class="related" role="navigation" aria-label="related navigation">
<h3>Navigation</h3>
<ul>
<li class="right" style="margin-right: 10px">
<a href="../genindex.html" title="General Index"
accesskey="I">index</a></li>
<li class="right" >
<a href="../historical/multi_ruleset_legacy_format_samples.html" title="Legacy Format Samples for Multiple Rulesets"
accesskey="N">next</a> |</li>
<li class="right" >
<a href="messageparser.html" title="Message parsers in rsyslog"
accesskey="P">previous</a> |</li>
<li class="nav-item nav-item-0"><a href="../index.html">rsyslog 8.2006.0 documentation</a> »</li>
<li class="nav-item nav-item-1"><a href="index.html" accesskey="U">Concepts</a> »</li>
</ul>
</div>
<div class="document">
<div class="documentwrapper">
<div class="bodywrapper">
<div class="body" role="main">
<div class="section" id="multiple-rulesets-in-rsyslog">
<h1>Multiple Rulesets in rsyslog<a class="headerlink" href="#multiple-rulesets-in-rsyslog" title="Permalink to this headline">¶</a></h1>
<p>Starting with version 4.5.0 and 5.1.1,
<a class="reference external" href="http://www.rsyslog.com">rsyslog</a> supports multiple rulesets within a
single configuration. This is especially useful for routing the
reception of remote messages to a set of specific rules. Note that the
input module must support binding to non-standard rulesets, so the
functionality may not be available with all inputs.</p>
<p>In this document, I am using <a class="reference internal" href="../configuration/modules/imtcp.html"><span class="doc">imtcp</span></a>, an input module that
supports binding to non-standard rulesets since rsyslog started to
support them.</p>
<div class="section" id="what-is-a-ruleset">
<h2>What is a Ruleset?<a class="headerlink" href="#what-is-a-ruleset" title="Permalink to this headline">¶</a></h2>
<p>If you have worked with (r)syslog.conf, you know that it is made up of
what I call rules (others tend to call them selectors, a sysklogd term).
Each rule consist of a filter and one or more actions to be carried out
when the filter evaluates to true. A filter may be as simple as a
traditional syslog priority based filter (like “*.*” or “mail.info” or
a as complex as a script-like expression. Details on that are covered in
the config file documentation. After the filter come action specifiers,
and an action is something that does something to a message, e.g. write
it to a file or forward it to a remote logging server.</p>
<p>A traditional configuration file is made up of one or more of these
rules. When a new message arrives, its processing starts with the first
rule (in order of appearance in rsyslog.conf) and continues for each
rule until either all rules have been processed or a so-called “discard”
action happens, in which case processing stops and the message is thrown
away (what also happens after the last rule has been processed).</p>
<p>The <strong>multi-ruleset</strong> support now permits to specify more than one such
rule sequence. You can think of a traditional config file just as a
single default rule set, which is automatically bound to each of the
inputs. This is even what actually happens. When rsyslog.conf is
processed, the config file parser looks for the directive</p>
<div class="highlight-default"><div class="highlight"><pre><span></span><span class="n">ruleset</span><span class="p">(</span><span class="n">name</span><span class="o">=</span><span class="s2">"rulesetname"</span><span class="p">)</span>
</pre></div>
</div>
<p>Where name is any name the user likes (but must not start with
“RSYSLOG_”, which is the name space reserved for rsyslog use). If it
finds this directive, it begins a new rule set (if the name was not yet
know) or switches to an already-existing one (if the name was known).
All rules defined between this $RuleSet directive and the next one are
appended to the named ruleset. Note that the reserved name
“RSYSLOG_DefaultRuleset” is used to specify rsyslogd’s default ruleset.
You can use that name wherever you can use a ruleset name, including
when binding an input to it.</p>
<p>Inside a ruleset, messages are processed as described above: they start
with the first rule and rules are processed in the order of appearance
of the configuration file until either there are no more rules or the
discard action is executed. Note that with multiple rulesets no longer
<strong>all</strong> rsyslog.conf rules are executed but <strong>only</strong> those that are
contained within the specific ruleset.</p>
<p>Inputs must explicitly bind to rulesets. If they don’t, the default
ruleset is bound.</p>
<p>This brings up the next question:</p>
</div>
<div class="section" id="what-does-to-bind-to-a-ruleset-mean">
<h2>What does “To bind to a Ruleset” mean?<a class="headerlink" href="#what-does-to-bind-to-a-ruleset-mean" title="Permalink to this headline">¶</a></h2>
<p>This term is used in the same sense as “to bind an IP address to an
interface”: it means that a specific input, or part of an input (like a
tcp listener) will use a specific ruleset to “pass its messages to”. So
when a new message arrives, it will be processed via the bound ruleset.
Rules from all other rulesets are irrelevant and will never be processed.</p>
<p>This makes multiple rulesets very handy to process local and remote
message via separate means: bind the respective receivers to different
rule sets, and you do not need to separate the messages by any other
method.</p>
<p>Binding to rulesets is input-specific. For imtcp, this is done via the</p>
<div class="highlight-default"><div class="highlight"><pre><span></span><span class="nb">input</span><span class="p">(</span><span class="nb">type</span><span class="o">=</span><span class="s2">"imptcp"</span> <span class="n">port</span><span class="o">=</span><span class="s2">"514"</span> <span class="n">ruleset</span><span class="o">=</span><span class="s2">"rulesetname"</span><span class="p">)</span>
</pre></div>
</div>
<p>directive. Note that “rulesetname” must be the name of a ruleset that is
already defined at the time the bind directive is given. There are many
ways to make sure this happens, but I personally think that it is best
to define all rule sets at the top of rsyslog.conf and define the inputs
at the bottom. This kind of reverses the traditional recommended
ordering, but seems to be a really useful and straightforward way of
doing things.</p>
</div>
<div class="section" id="why-are-rulesets-important-for-different-parser-configurations">
<h2>Why are rulesets important for different parser configurations?<a class="headerlink" href="#why-are-rulesets-important-for-different-parser-configurations" title="Permalink to this headline">¶</a></h2>
<p>Custom message parsers, used to handle different (and potentially
otherwise-invalid) message formats, can be bound to rulesets. So
multiple rulesets can be a very useful way to handle devices sending
messages in different malformed formats in a consistent way.
Unfortunately, this is not uncommon in the syslog world. An in-depth
explanation with configuration sample can be found at the
<a class="reference internal" href="../configuration/ruleset/rsconf1_rulesetparser.html"><span class="doc">$RulesetParser</span></a> configuration directive.</p>
</div>
<div class="section" id="can-i-use-a-different-ruleset-as-the-default">
<h2>Can I use a different Ruleset as the default?<a class="headerlink" href="#can-i-use-a-different-ruleset-as-the-default" title="Permalink to this headline">¶</a></h2>
<p>This is possible by using the</p>
<div class="highlight-default"><div class="highlight"><pre><span></span>$DefaultRuleset <name>
</pre></div>
</div>
<p>Directive. Please note, however, that this directive is actually global:
that is, it does not modify the ruleset to which the next input is bound
but rather provides a system-wide default rule set for those inputs that
did not explicitly bind to one. As such, the directive can not be used
as a work-around to bind inputs to non-default rulesets that do not
support ruleset binding.</p>
</div>
<div class="section" id="rulesets-and-queues">
<h2>Rulesets and Queues<a class="headerlink" href="#rulesets-and-queues" title="Permalink to this headline">¶</a></h2>
<p>By default, rulesets do not have their own queue. It must be activated
via the $RulesetCreateMainQueue directive, or if using rainerscript
format, by specifying queue parameters on the ruleset directive, e.g.</p>
<div class="highlight-default"><div class="highlight"><pre><span></span><span class="n">ruleset</span><span class="p">(</span><span class="n">name</span><span class="o">=</span><span class="s2">"whatever"</span> <span class="n">queue</span><span class="o">.</span><span class="n">type</span><span class="o">=</span><span class="s2">"fixedArray"</span> <span class="n">queue</span><span class="o">.</span> <span class="o">...</span><span class="p">)</span>
</pre></div>
</div>
<p>See <a class="reference internal" href="../rainerscript/queue_parameters.html"><span class="doc">http://www.ryslog.com/doc/master/rainerscript/queue_parameters.html</span></a>
for more details.</p>
<p>Please note that when a ruleset uses its own queue, processing of the ruleset
happens <strong>asynchronously</strong> to the rest of processing. As such, any modifications
made to the message object (e.g. message or local variables that are set) or
discarding of the message object <strong>have no effect outside that ruleset</strong>. So
if you want to modify the message object inside the ruleset, you <strong>cannot</strong>
define a queue for it. Most importantly, you cannot call it and expect the
modified properties to be present when the call returns. Even more so, the
call will most probably return before the message is even begun to be processed
by the ruleset in question.</p>
<p>Note that in RainerScript format specifying any “queue.*” can cause the
creation of a dedicated queue and as such asynchronous processing. This is
because queue parameters cannot be specified without a queue. Note, though,
that the actual creation is <strong>guaranteed</strong> only if “queue.type” is specified
as above. So if you intentionally want to assign a separate queue to the
ruleset, do so as shown above.</p>
</div>
<div class="section" id="examples">
<h2>Examples<a class="headerlink" href="#examples" title="Permalink to this headline">¶</a></h2>
<div class="section" id="split-local-and-remote-logging">
<h3>Split local and remote logging<a class="headerlink" href="#split-local-and-remote-logging" title="Permalink to this headline">¶</a></h3>
<p>Let’s say you have a pretty standard system that logs its local messages
to the usual bunch of files that are specified in the default
rsyslog.conf. As an example, your rsyslog.conf might look like this:</p>
<div class="highlight-default"><div class="highlight"><pre><span></span><span class="c1"># ... module loading ...</span>
<span class="c1"># The authpriv file has restricted access.</span>
<span class="n">authpriv</span><span class="o">.*</span> <span class="o">/</span><span class="n">var</span><span class="o">/</span><span class="n">log</span><span class="o">/</span><span class="n">secure</span>
<span class="c1"># Log all the mail messages in one place.</span>
<span class="n">mail</span><span class="o">.*</span> <span class="o">/</span><span class="n">var</span><span class="o">/</span><span class="n">log</span><span class="o">/</span><span class="n">maillog</span>
<span class="c1"># Log cron stuff</span>
<span class="n">cron</span><span class="o">.*</span> <span class="o">/</span><span class="n">var</span><span class="o">/</span><span class="n">log</span><span class="o">/</span><span class="n">cron</span>
<span class="c1"># Everybody gets emergency messages</span>
<span class="o">*.</span><span class="n">emerg</span> <span class="o">*</span>
<span class="o">...</span> <span class="n">more</span> <span class="o">...</span>
</pre></div>
</div>
<p>Now, you want to add receive messages from a remote system and log these
to a special file, but you do not want to have these messages written to
the files specified above. The traditional approach is to add a rule in
front of all others that filters on the message, processes it and then
discards it:</p>
<div class="highlight-default"><div class="highlight"><pre><span></span># ... module loading ...
# process remote messages
if $fromhost-ip == '192.0.2.1' then {
action(type="omfile" file="/var/log/remotefile02")
stop
}
# only messages not from 192.0.2.1 make it past this point
# The authpriv file has restricted access.
authpriv.* /var/log/secure
# Log all the mail messages in one place.
mail.* /var/log/maillog
# Log cron stuff
cron.* /var/log/cron
# Everybody gets emergency messages
*.emerg *
... more ...
</pre></div>
</div>
<p>Note that “stop” is the discard action!. Also note that we assume that
192.0.2.1 is the sole remote sender (to keep it simple).</p>
<p>With multiple rulesets, we can simply define a dedicated ruleset for the
remote reception case and bind it to the receiver. This may be written
as follows:</p>
<div class="highlight-default"><div class="highlight"><pre><span></span><span class="c1"># ... module loading ...</span>
<span class="c1"># process remote messages</span>
<span class="c1"># define new ruleset and add rules to it:</span>
<span class="n">ruleset</span><span class="p">(</span><span class="n">name</span><span class="o">=</span><span class="s2">"remote"</span><span class="p">){</span>
<span class="n">action</span><span class="p">(</span><span class="nb">type</span><span class="o">=</span><span class="s2">"omfile"</span> <span class="n">file</span><span class="o">=</span><span class="s2">"/var/log/remotefile"</span><span class="p">)</span>
<span class="p">}</span>
<span class="c1"># only messages not from 192.0.21 make it past this point</span>
<span class="c1"># bind ruleset to tcp listener and activate it:</span>
<span class="nb">input</span><span class="p">(</span><span class="nb">type</span><span class="o">=</span><span class="s2">"imptcp"</span> <span class="n">port</span><span class="o">=</span><span class="s2">"10514"</span> <span class="n">ruleset</span><span class="o">=</span><span class="s2">"remote"</span><span class="p">)</span>
</pre></div>
</div>
</div>
<div class="section" id="split-local-and-remote-logging-for-three-different-ports">
<h3>Split local and remote logging for three different ports<a class="headerlink" href="#split-local-and-remote-logging-for-three-different-ports" title="Permalink to this headline">¶</a></h3>
<p>This example is almost like the first one, but it extends it a little
bit. While it is very similar, I hope it is different enough to provide
a useful example why you may want to have more than two rulesets.</p>
<p>Again, we would like to use the “regular” log files for local logging,
only. But this time we set up three syslog/tcp listeners, each one
listening to a different port (in this example 10514, 10515, and 10516).
Logs received from these receivers shall go into different files. Also,
logs received from 10516 (and only from that port!) with “mail.*”
priority, shall be written into a specific file and <strong>not</strong> be written to
10516’s general log file.</p>
<p>This is the config:</p>
<div class="highlight-default"><div class="highlight"><pre><span></span><span class="c1"># ... module loading ...</span>
<span class="c1"># process remote messages</span>
<span class="n">ruleset</span><span class="p">(</span><span class="n">name</span><span class="o">=</span><span class="s2">"remote10514"</span><span class="p">){</span>
<span class="n">action</span><span class="p">(</span><span class="nb">type</span><span class="o">=</span><span class="s2">"omfile"</span> <span class="n">file</span><span class="o">=</span><span class="s2">"/var/log/remote10514"</span><span class="p">)</span>
<span class="p">}</span>
<span class="n">ruleset</span><span class="p">(</span><span class="n">name</span><span class="o">=</span><span class="s2">"remote10515"</span><span class="p">){</span>
<span class="n">action</span><span class="p">(</span><span class="nb">type</span><span class="o">=</span><span class="s2">"omfile"</span> <span class="n">file</span><span class="o">=</span><span class="s2">"/var/log/remote10515"</span><span class="p">)</span>
<span class="p">}</span>
<span class="n">ruleset</span><span class="p">(</span><span class="n">name</span><span class="o">=</span><span class="s2">"remote10516"</span><span class="p">){</span>
<span class="k">if</span> <span class="n">prifilt</span><span class="p">(</span><span class="s2">"mail.*"</span><span class="p">)</span> <span class="n">then</span> <span class="p">{</span>
<span class="o">/</span><span class="n">var</span><span class="o">/</span><span class="n">log</span><span class="o">/</span><span class="n">mail10516</span>
<span class="n">stop</span>
<span class="c1"># note that the stop-command will prevent this message from</span>
<span class="c1"># being written to the remote10516 file - as usual...</span>
<span class="p">}</span>
<span class="o">/</span><span class="n">var</span><span class="o">/</span><span class="n">log</span><span class="o">/</span><span class="n">remote10516</span>
<span class="p">}</span>
<span class="c1"># and now define listeners bound to the relevant ruleset</span>
<span class="nb">input</span><span class="p">(</span><span class="nb">type</span><span class="o">=</span><span class="s2">"imptcp"</span> <span class="n">port</span><span class="o">=</span><span class="s2">"10514"</span> <span class="n">ruleset</span><span class="o">=</span><span class="s2">"remote10514"</span><span class="p">)</span>
<span class="nb">input</span><span class="p">(</span><span class="nb">type</span><span class="o">=</span><span class="s2">"imptcp"</span> <span class="n">port</span><span class="o">=</span><span class="s2">"10515"</span> <span class="n">ruleset</span><span class="o">=</span><span class="s2">"remote10515"</span><span class="p">)</span>
<span class="nb">input</span><span class="p">(</span><span class="nb">type</span><span class="o">=</span><span class="s2">"imptcp"</span> <span class="n">port</span><span class="o">=</span><span class="s2">"10516"</span> <span class="n">ruleset</span><span class="o">=</span><span class="s2">"remote10516"</span><span class="p">)</span>
</pre></div>
</div>
</div>
</div>
<div class="section" id="performance">
<h2>Performance<a class="headerlink" href="#performance" title="Permalink to this headline">¶</a></h2>
<div class="section" id="fewer-filters">
<h3>Fewer Filters<a class="headerlink" href="#fewer-filters" title="Permalink to this headline">¶</a></h3>
<p>No rule processing can be faster than not processing a rule at all. As
such, it is useful for a high performance system to identify disjunct
actions and try to split these off to different rule sets. In the
example section, we had a case where three different tcp listeners need
to write to three different files. This is a perfect example of where
multiple rule sets are easier to use and offer more performance. The
performance is better simply because there is no need to check the
reception service - instead messages are automatically pushed to the
right rule set and can be processed by very simple rules (maybe even
with “*.*”-filters, the fastest ones available).</p>
</div>
<div class="section" id="partitioning-of-input-data">
<h3>Partitioning of Input Data<a class="headerlink" href="#partitioning-of-input-data" title="Permalink to this headline">¶</a></h3>
<p>Starting with rsyslog 5.3.4, rulesets permit higher concurrency. They
offer the ability to run on their own “main” queue. What that means is
that a own queue is associated with a specific rule set. That means that
inputs bound to that ruleset do no longer need to compete with each
other when they enqueue a data element into the queue. Instead, enqueue
operations can be completed in parallel.</p>
<p>An example: let us assume we have three TCP listeners. Without rulesets,
each of them needs to insert messages into the main message queue. So if
each of them wants to submit a newly arrived message into the queue at
the same time, only one can do so while the others need to wait. With
multiple rulesets, its own queue can be created for each ruleset. If now
each listener is bound to its own ruleset, concurrent message submission
is possible. On a machine with a sufficiently large number of cores,
this can result in dramatic performance improvement.</p>
<p>It is highly advised that high-performance systems define a dedicated
ruleset, with a dedicated queue for each of the inputs.</p>
<p>By default, rulesets do <strong>not</strong> have their own queue. It must be
activated via the
<a class="reference internal" href="../configuration/ruleset/rsconf1_rulesetcreatemainqueue.html"><span class="doc">$RulesetCreateMainQueue</span></a>
directive.</p>
</div>
</div>
<div class="section" id="see-also">
<h2>See Also<a class="headerlink" href="#see-also" title="Permalink to this headline">¶</a></h2>
<div class="toctree-wrapper compound">
<ul>
<li class="toctree-l1"><a class="reference internal" href="../historical/multi_ruleset_legacy_format_samples.html">Legacy Format Samples for Multiple Rulesets</a></li>
</ul>
</div>
<div class="admonition seealso">
<p class="first admonition-title">See also</p>
<p>Help with configuring/using <code class="docutils literal"><span class="pre">Rsyslog</span></code>:</p>
<ul class="last simple">
<li><a class="reference external" href="http://lists.adiscon.net/mailman/listinfo/rsyslog">Mailing list</a> - best route for general questions</li>
<li>GitHub: <a class="reference external" href="https://github.com/rsyslog/rsyslog/">rsyslog source project</a> - detailed questions, reporting issues
that are believed to be bugs with <code class="docutils literal"><span class="pre">Rsyslog</span></code></li>
<li>Stack Exchange (<a class="reference external" href="https://stackexchange.com/filters/327462/rsyslog">View</a>, <a class="reference external" href="https://serverfault.com/questions/ask?tags=rsyslog">Ask</a>)
- experimental support from rsyslog community</li>
</ul>
</div>
<div class="admonition seealso">
<p class="first admonition-title">See also</p>
<p>Contributing to <code class="docutils literal"><span class="pre">Rsyslog</span></code>:</p>
<ul class="last simple">
<li>Source project: <a class="reference external" href="https://github.com/rsyslog/rsyslog/blob/master/README.md">rsyslog project README</a>.</li>
<li>Documentation: <a class="reference external" href="https://github.com/rsyslog/rsyslog-doc/blob/master/README.md">rsyslog-doc project README</a></li>
</ul>
</div>
<p>Copyright 2008-2020 <a class="reference external" href="https://rainer.gerhards.net/">Rainer Gerhards</a>
(<a class="reference external" href="https://www.rainer-gerhards.de/grossrinderfeld/">Großrinderfeld</a>),
and Others.</p>
</div>
</div>
</div>
</div>
</div>
<div class="sphinxsidebar" role="navigation" aria-label="main navigation">
<div class="sphinxsidebarwrapper">
<h3><a href="../index.html">Table Of Contents</a></h3>
<ul>
<li><a class="reference internal" href="#">Multiple Rulesets in rsyslog</a><ul>
<li><a class="reference internal" href="#what-is-a-ruleset">What is a Ruleset?</a></li>
<li><a class="reference internal" href="#what-does-to-bind-to-a-ruleset-mean">What does “To bind to a Ruleset” mean?</a></li>
<li><a class="reference internal" href="#why-are-rulesets-important-for-different-parser-configurations">Why are rulesets important for different parser configurations?</a></li>
<li><a class="reference internal" href="#can-i-use-a-different-ruleset-as-the-default">Can I use a different Ruleset as the default?</a></li>
<li><a class="reference internal" href="#rulesets-and-queues">Rulesets and Queues</a></li>
<li><a class="reference internal" href="#examples">Examples</a><ul>
<li><a class="reference internal" href="#split-local-and-remote-logging">Split local and remote logging</a></li>
<li><a class="reference internal" href="#split-local-and-remote-logging-for-three-different-ports">Split local and remote logging for three different ports</a></li>
</ul>
</li>
<li><a class="reference internal" href="#performance">Performance</a><ul>
<li><a class="reference internal" href="#fewer-filters">Fewer Filters</a></li>
<li><a class="reference internal" href="#partitioning-of-input-data">Partitioning of Input Data</a></li>
</ul>
</li>
<li><a class="reference internal" href="#see-also">See Also</a></li>
</ul>
</li>
</ul>
<h4>Previous topic</h4>
<p class="topless"><a href="messageparser.html"
title="previous chapter">Message parsers in rsyslog</a></p>
<h4>Next topic</h4>
<p class="topless"><a href="../historical/multi_ruleset_legacy_format_samples.html"
title="next chapter">Legacy Format Samples for Multiple Rulesets</a></p>
<h3>This Page</h3>
<ul class="this-page-menu">
<li><a href="../_sources/concepts/multi_ruleset.rst.txt"
rel="nofollow">Show Source</a></li>
<li><a href="https://github.com/rsyslog/rsyslog-doc/edit/master/source/concepts/multi_ruleset.rst"
rel="nofollow">Edit on GitHub</a></li>
</ul>
<div id="searchbox" style="display: none" role="search">
<h3>Quick search</h3>
<form class="search" action="../search.html" method="get">
<div><input type="text" name="q" /></div>
<div><input type="submit" value="Go" /></div>
<input type="hidden" name="check_keywords" value="yes" />
<input type="hidden" name="area" value="default" />
</form>
</div>
<script type="text/javascript">$('#searchbox').show(0);</script>
</div>
</div>
<div class="clearer"></div>
</div>
<div class="related" role="navigation" aria-label="related navigation">
<h3>Navigation</h3>
<ul>
<li class="right" style="margin-right: 10px">
<a href="../genindex.html" title="General Index"
>index</a></li>
<li class="right" >
<a href="../historical/multi_ruleset_legacy_format_samples.html" title="Legacy Format Samples for Multiple Rulesets"
>next</a> |</li>
<li class="right" >
<a href="messageparser.html" title="Message parsers in rsyslog"
>previous</a> |</li>
<li class="nav-item nav-item-0"><a href="../index.html">rsyslog 8.2006.0 documentation</a> »</li>
<li class="nav-item nav-item-1"><a href="index.html" >Concepts</a> »</li>
</ul>
</div>
<div class="footer" role="contentinfo">
</div>
</body>
</html>