Another alternative to regular expression based message parsing that has native support within syslog-ng: patterndb (<a href="http://www.balabit.com/network-security/syslog-ng/opensource-logging-system/features/pattern-db" rel="nofollow">http://www.balabit.com/network-security/syslog-ng/opensource...</a>)<p>Very fast and a bit complex to setup, but well documented and well tooled. Mature. It could do with some more community love, tbh.