The ENUM{ 'string'=integer, ... } constructor matches a set of predefined strings and converts each to its assigned integer value. The strings and their integer values are declared as a series of key-value pairs, separated by commas and enclosed in curly brackets.
Use the following expression to parse the value:
ENUM{'INFO'=2, 'WARN'=3, 'ERROR'=4}:result
For example, mapping log-level strings to integers:
| Description | input (string) | result (long) |
|---|---|---|
Declared value |
|
|
Declared value |
|
|
Declared value |
|
|
Case mismatch |
|
|
Value not in the enum |
|
|
Whitespace |
|
|
data record(input = "INFO"),record(input = "WARN"),record(input = "ERROR"),record(input = "error"),record(input = "TRACE"),record(input = " ")| parse input, "ENUM{'INFO'=2, 'WARN'=3, 'ERROR'=4}:result"
Specify configuration parameters in parentheses after the closing brace: ENUM{ 'string'=integer, ... }(param=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| Matches string values case-insensitively, so |
|
| String specifying an IETF BCP 47 language tag enclosed in single or double quotes. Default: |
|
| Character set name enclosed in single or double quotes (for example |
The data type of the extracted value is long.
The cis=true configuration makes the enum keys match regardless of case, while values that are not declared still return null.
Use the following expression to map log levels to integers:
ENUM{'INFO'=2, 'WARN'=3, 'ERROR'=4}(cis=true):result
input (string) | result (long) |
|---|---|
|
|
|
|
|
|
|
|
data record(input = "INFO"),record(input = "info"),record(input = "Error"),record(input = "unknown")| parse input, "ENUM{'INFO'=2, 'WARN'=3, 'ERROR'=4}(cis=true):result"
Text severities such as WARN and ERROR can't be compared or sorted meaningfully. Mapping them to an ordinal integer makes range filters and sorting possible. For example, | filter severity >= 3 selects warnings and above.
Given the following input:
2024-05-01T10:00:00Z ERROR Database connection lost
Use the following expression to extract the severity as an integer, and the message:
LD ENUM{'TRACE'=0, 'DEBUG'=1, 'INFO'=2, 'WARN'=3, 'ERROR'=4, 'FATAL'=5}(cis=true):severity SPACE LD:message
severity (long) | message (string) |
|---|---|
|
|
data record(input = "2024-05-01T10:00:00Z ERROR Database connection lost")| parse input, "LD ENUM{'TRACE'=0, 'DEBUG'=1, 'INFO'=2, 'WARN'=3, 'ERROR'=4, 'FATAL'=5}(cis=true):severity SPACE LD:message"
An enum key of '' (empty string) matches a present-but-blank field, which is the documented way to supply a default value. When the field is guarded by a following matcher (here the trailing ;), a non-blank value that is not declared fails the match instead of falling back to the default.
Use the following expression to extract the username, map the login result to an integer, and extract the comment:
LD:username ';' ENUM{''=-3, 'success'=0, 'Wrong password'=1, 'tech error'=2}(cis=true):result ';' LD*:comment
input (string) | username (string) | result (long) | comment (string) |
|---|---|---|---|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
data record(input = "Alice;success;all good"),record(input = "Bob;Wrong password;attempts left 2"),record(input = "Oscar;tech error;"),record(input = "Mallory;;doodaloo")| parse input, "LD:username ';' ENUM{''=-3, 'success'=0, 'Wrong password'=1, 'tech error'=2}(cis=true):result ';' LD*:comment"
Extract region only when it’s one of the allowed values declared in ENUM. Unknown region values don’t match the pattern and the parsed result is null.
Use the following expression to extract only recognized regions:
'region=' ENUM{'emea'=1, 'apac'=2, 'amer'=3}:result
input (string) | result (long) |
|---|---|
|
|
|
|
data record(input = "region=emea host=web01"),record(input = "region=xyz host=web02")| parse input, "'region=' ENUM{'emea'=1, 'apac'=2, 'amer'=3}:result"
Combined with parseAll, a single-entry enum matches every occurrence of a string, and arraySize counts them—useful for finding records that contain a term more than a given number of times.
Use the following expression to count how many times ERROR appears in each record:
ENUM{'ERROR'=0}(cis=true):status
input (string) | result (array) | occurrences (long) |
|---|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
data record(input = "no"),record(input = "one ErrOR"),record(input = "an ERRORERROR log"),record(input = "1 ERROR 2 ERROR 3 ERROR and ERROR")| fieldsAdd result = parseAll(input, "ENUM{'ERROR'=0}(cis=true):status")| fieldsAdd occurrences = arraySize(result)