# Mutiple journal filters in the same acquisition stanza?

**URL:** <https://discourse.crowdsec.net/t/mutiple-journal-filters-in-the-same-acquisition-stanza/2376>\
**Category:** crowdsec\
**Created:** [February 19, 2025, 11:35am UTC](https://discourse.crowdsec.net/t/mutiple-journal-filters-in-the-same-acquisition-stanza/2376 "2025-02-19T11:35:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Headwear1](https://avatars.discourse-cdn.com/v4/letter/h/a88e57/32.png) [@Headwear1](https://discourse.crowdsec.net/u/Headwear1)\
**Post date:** [February 19, 2025, 11:35am UTC](https://discourse.crowdsec.net/t/mutiple-journal-filters-in-the-same-acquisition-stanza/2376/1 "2025-02-19T11:35:43Z")

</div>

Hi,

It’s not clear to me how the different acquisitons are related to the parsers. For example, can I group all my journal filters in a single stanza like this?:

```yaml
source: journalctl
journalctl_filter:
  - "-D"
  - "/var/log/journal"
  - "_SYSTEMD_UNIT=forgejo.service"
  - "_SYSTEMD_UNIT=jellyseerr.service"
  - "_SYSTEMD_UNIT=jellyfin.service"
  - "_SYSTEMD_UNIT=authelia.service"
  - "_SYSTEMD_UNIT=immich-server.service"
  - "_SYSTEMD_UNIT=audiobookshelf.service"
labels:
  type: syslog

```

I understand that `type: syslog` is required for all journal acquisitions, but how does the parser know which logs to use? When using log files you use for example `type: authelia` which makes apparent that the authelia parse will use that. It’s unclear how this works.

Do all the parsers parse everything from the journal?

Thank you.

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [February 19, 2025, 12:11pm UTC](https://discourse.crowdsec.net/t/mutiple-journal-filters-in-the-same-acquisition-stanza/2376/2 "2025-02-19T12:11:30Z")

</div>

So the way it works is there is multiple stages typically `s00-raw` , `s01-parse` and `s02-enrich`. Within `s00` this stage is used to normalize the log lines if your reading from syslog or from a file its a pre parse to the application logic which is in `s01`.

So for example a typical `syslog` log line holds the “program” name within the line:

```auto
<timestamp> <host> <program>[<pid>] <message>

```

This means as long as the parser and the `<program>` has the same naming then this is what is used to inform the `s01` stage of which parser to use. Now when it comes to `file` acquisition there is no program name within the log line so that is when we expect you to set `labels.type` to the program name itself.

**Not every parser has been tested via syslog, so for example if you try it and it doesnt work then providing example syslog lines may aid us in debugging further.**

---

<div class="post-metadata">

**Author:** ![Headwear1](https://avatars.discourse-cdn.com/v4/letter/h/a88e57/32.png) [@Headwear1](https://discourse.crowdsec.net/u/Headwear1)\
**Post date:** [February 20, 2025, 1:54pm UTC](https://discourse.crowdsec.net/t/mutiple-journal-filters-in-the-same-acquisition-stanza/2376/3 "2025-02-20T13:54:45Z")

</div>

Thanks for the explanation. I’ll look into it to be sure that it’s matching the program.
