Matches the single line feed character (\n, ASCII 0x0A). EOL is used as a line terminator or separator in patterns alongside other matchers.
Use the following expression to match a line separator between two values:
WORD:name EOL WORD:surname
Given the following input:
John\nDoe
name (string) | surname (string) |
|---|---|
|
|
data record(input = "John\nDoe")| parse input, "WORD:name EOL WORD:surname"
By default, EOL matches exactly one line feed character. Append a quantifier to match multiple consecutive line feeds: EOL{min,max}.
| Parameter | Type | Description |
|---|---|---|
|
| Minimum number of occurrences, as a non-negative integer. Parsing fails and the output returns |
|
| Maximum number of occurrences to match, greater than or equal to |
EOL is typically used without a capture name as a line terminator or separator. When captured (EOL:result), the data type of the extracted value is string.
Given the following input:
input (string) |
|---|
|
Use the following expression to extract the value:
ARRAY{ DATA ([0-9]{1,2} '.' [0-9]{2} >> (EOL|EOS)):i }{1,}:result
The >> lookahead anchors the number pattern to the position just before a line end or the end of the input, so DATA skips each line's leading columns and only the trailing Used % value is captured per line. Header and separator lines contain no such number and are consumed by DATA without producing an array element. The (EOL|EOS) alternation also captures the value on the last line when the input has no trailing newline.
result (array) |
|---|
|
data record(input = """Status Name Type Extent Man Initial Extent Size (M) Used (MB) Used %--------- -------------- ---------- --------------- ------------------ ------------ ------------ --------------ONLINE SAMPLE_INDEX_X GROUP_ONE EXT_A 65536 908,304.000 905,890.125 99.73ONLINE SAMPLE_INDEX_X GROUP_ONE EXT_A 65536 908,304.000 905,890.125 99.72ONLINE SAMPLE_INDEX_X GROUP_ONE EXT_A 65536 908,304.000 905,890.125 99.71ONLINE SAMPLE_INDEX_X GROUP_ONE EXT_A 65536 908,304.000 905,890.125 99.79""")| parse input, "ARRAY{ DATA ([0-9]{1,2} '.' [0-9]{2} >> (EOL|EOS)):i }{1,}:result"| fields result
Matches the single carriage return character (CR, \r, ASCII 0x0D). CR is used as a line terminator or separator in patterns alongside other matchers.
Use the following expression to match a line separator between two values:
WORD:name CR WORD:surname
Given the following input:
John\rDoe
name (string) | surname (string) |
|---|---|
|
|
data record(input = "John\rDoe")| parse input, "WORD:name CR WORD:surname"
By default, CR matches exactly one carriage return character. Append a quantifier to match multiple consecutive carriage returns: CR{min,max}.
| Parameter | Type | Description |
|---|---|---|
|
| Minimum number of occurrences, as a non-negative integer. Parsing fails and the output returns |
|
| Maximum number of occurrences to match, greater than or equal to |
CR is typically used without a capture name as a line terminator or separator. When captured (CR:result), the data type of the extracted value is string.
Given the following input (CR-only line endings, as produced by legacy Mac OS and some embedded systems):
ERROR: disk full\rWARN: low memory\rINFO: backup complete
Use the following expression to extract the value:
ARRAY{LD:item (CR|EOS)}{1,}:result
(CR|EOS) handles both the CR between records and the end-of-string after the last record, so no trailing CR is required on the final line.
result (array) |
|---|
|
data record(input = "ERROR: disk full\rWARN: low memory\rINFO: backup complete")| parse input, "ARRAY{LD:item (CR|EOS)}{1,}:result"| fields result
Matches the Windows line ending sequence (CRLF, \r\n, ASCII 0x0D 0x0A). EOLWIN is used as a line terminator or separator in patterns alongside other matchers.
Use the following expression to match a Windows line separator between two values:
WORD:name EOLWIN WORD:surname
Given the following input:
John\r\nDoe
name (string) | surname (string) |
|---|---|
|
|
data record(input = "John\r\nDoe")| parse input, "WORD:name EOLWIN WORD:surname"
By default, EOLWIN matches exactly one Windows line ending sequence. Append a quantifier to match multiple consecutive sequences: EOLWIN{min,max}.
| Parameter | Type | Description |
|---|---|---|
|
| Minimum number of occurrences, as a non-negative integer. Parsing fails and the output returns |
|
| Maximum number of occurrences to match, greater than or equal to |
EOLWIN is typically used without a capture name as a line terminator or separator. When captured (EOLWIN:result), the data type of the extracted value is string.
Given the following input (Windows Event ID 4625—failed logon):
An account failed to log on.\r\n\r\nFailed:\r\n\tSecurity ID:\t\tNULL SID\r\n\tAccount Name:\t\tjdoe\r\n\tAccount Domain:\t\tCORPDOMAIN\r\n\tLogon Type:\t\t3\r\n\r\nFailure Information:\r\n\tFailure Reason:\t\tUnknown user name or bad password.\r\n\tStatus:\t\t\t0xC000006D\r\n\tSub Status:\t\t0xC0000064\r\n
Use the following expression to extract the value:
DATA 'Account Name:' BLANK LD?:'login.attempt.user' EOLWIN DATA 'Account Domain:' BLANK LD?:'login.attempt.domain'
login.attempt.user (string) | login.attempt.domain (string) |
|---|---|
|
|
data record(input = "An account failed to log on.\r\n\r\nFailed:\r\n\tSecurity ID:\t\tNULL SID\r\n\tAccount Name:\t\tjdoe\r\n\tAccount Domain:\t\tCORPDOMAIN\r\n\tLogon Type:\t\t3\r\n\r\nFailure Information:\r\n\tFailure Reason:\t\tUnknown user name or bad password.\r\n\tStatus:\t\t\t0xC000006D\r\n\tSub Status:\t\t0xC0000064\r\n")| parse input, "DATA 'Account Name:' BLANK LD?:'login.attempt.user' EOLWIN DATA 'Account Domain:' BLANK LD?:'login.attempt.domain'"
LD, LDATA
Matches any characters until the next non-optional matcher in the scope of a line.
LD must always be followed by a non-optional matcher expression.
Use the following expression to parse the value:
LD:result
For example:
| Description | input (string) | result (string) |
|---|---|---|
Single-line text |
|
|
Text containing a newline |
|
|
data record(input = "Red fox jumps"),record(input = "line one\nline two")| parse input, "LD:result"
Specify configuration parameters in parentheses after the matcher name: LD(param=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| Character set name enclosed in single or double quotes (for example |
|
| String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none. |
By default, LD matches between 1 and 4096 characters. Append a quantifier to override: LD{min,max}:result.
| Parameter | Type | Description |
|---|---|---|
|
| Minimum number of characters to match, as a non-negative integer. Parsing fails and the output returns |
|
| Maximum number of characters to match, greater than or equal to |
The data type of the extracted value is string.
Given the following input:
Red fox jumps\nover lazy dog
Use the following expression to extract the value:
LD:first EOL LD:second
first (string) | second (string) |
|---|---|
|
|
data record(input = "Red fox jumps\nover lazy dog\n")| parse input, "LD:first EOL LD:second"
Given the following input:
2016-01-03 00:13:28,110.188.4.216,forerequest,200
Use the following expression to extract the value:
TIMESTAMP('yyyy-MM-dd HH:mm:ss'):ts ',' IPADDR:ip ',' LD:username ',' LD
ts (timestamp) | ip (string) | username (string) |
|---|---|---|
|
|
|
data record(input = "2016-01-03 00:13:28,110.188.4.216,forerequest,200\n")| parse input, "TIMESTAMP('yyyy-MM-dd HH:mm:ss'):ts ',' IPADDR:ip ',' LD:username ',' LD"
DATA
Matches any characters until the next non-optional matcher of pattern expression.
DATA must always be followed by a non-optional matcher expression.
Use the following expression to parse the value:
DATA:result
For example:
| Description | input (string) | result (string) |
|---|---|---|
Single-line text |
|
|
Text containing a newline |
|
|
data record(input = "Red fox jumps"),record(input = "line one\nline two")| parse input, "DATA:result"
Specify configuration parameters in parentheses after the matcher name: DATA(param=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| Character set name enclosed in single or double quotes (for example |
|
| String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none. |
By default, DATA matches between 1 and 4096 characters. Append a quantifier to override: DATA{min,max}:result.
| Parameter | Type | Description |
|---|---|---|
|
| Minimum number of characters to match, as a non-negative integer. Parsing fails and the output returns |
|
| Maximum number of characters to match, greater than or equal to |
The data type of the extracted value is string.
Given the following input:
2015.10.03 16:32:51.371 +0000 ERROR com.dt.webconsole.jsp.data.SQLTimeSeriesCache -- SQLTimeSeries remote fetch failed org.postgresql.util.PSQLException: Connection refused. Check that the hostname and port are correct and that the postmaster is accepting TCP/IP connections. at org.postgresql.core.ConnectionFactory.openConnection(ConnectionFactory.java:66) 2015-10-03 19:33:47.422 +0000 WARN main com.dt.wgui.WGUIMain Log processing started in /Users/user/dt, listening http://localhost:8390/, pid: 11364@abcdef
Use the following expression to extract the value:
DATA:result TIMESTAMP('yyyy-MM-dd HH:mm:ss.SSS Z'):next_ts
DATA matches any content, stopping at the first position where TIMESTAMP matches. The first record is captured in result, and the timestamp that starts the second record is captured in next_ts.
result (string) | next_ts (timestamp) |
|---|---|
|
|
data record(input = "2015.10.03 16:32:51.371 +0000 ERROR com.dt.webconsole.jsp.data.SQLTimeSeriesCache -- SQLTimeSeries remote fetch failed org.postgresql.util.PSQLException: Connection refused. Check that the hostname and port are correct and that the postmaster is accepting TCP/IP connections. at org.postgresql.core.ConnectionFactory.openConnection(ConnectionFactory.java:66) 2015-10-03 19:33:47.422 +0000 WARN main com.dt.wgui.WGUIMain Log processing started in /Users/user/dt, listening http://localhost:8390/, pid: 11364@abcdef")| parse input, """DATA:result TIMESTAMP('yyyy-MM-dd HH:mm:ss.SSS Z'):next_ts"""
Matches string enclosed between single quotes (ASCII 0x27). Any single quote inside the string must be escaped by backslash character \.
Use the following expression to parse the value:
SQS:result
For example:
| Description | input (string) | result (string) |
|---|---|---|
Single-quoted string |
|
|
Backslash-escaped single quote |
|
|
Tab inside the quotes |
|
|
Newline inside the quotes |
|
|
Double-quoted input |
|
|
Unclosed quote |
|
|
data record(input = "'hello world'"),record(input = "'it\\'s here'"),record(input = "'jdoe\tadmin'"),record(input = "'line one\nline two'"),record(input = "\"hello world\""),record(input = "'unclosed")| parse input, "SQS:result"
Specify configuration parameters in parentheses after the matcher name: SQS(param=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| Character set name enclosed in single or double quotes (for example |
|
| String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none. |
By default, SQS matches a quoted string of between 1 and 4096 characters, including the two enclosing quote characters. Append a quantifier to override: SQS{min,max}:result.
| Parameter | Type | Description |
|---|---|---|
|
| Minimum number of characters of the quoted string, including the two enclosing quote characters, as a non-negative integer. Parsing fails and the output returns |
|
| Maximum number of characters of the quoted string, including the two enclosing quote characters, greater than or equal to |
The data type of the extracted value is string.
Given the following input:
'Homer said: d\'oh!'
Use the following expression to extract the value:
SQS:result
result (string) |
|---|
|
data record(input = "'Homer said: d\\'oh!'")| parse input, "SQS:result"
Given the following input:
2026-02-24 05:18:34.1541876 Login failed for user 'jdoe'. Reason: Password did not match that for the login provided. [CLIENT: 192.10.0.1]
Use the following expression to extract the value:
LD "user " SQS:name
name (string) |
|---|
|
data record(input = "2026-02-24 05:18:34.1541876\tLogin failed for user 'jdoe'. Reason: Password did not match that for the login provided. [CLIENT: 192.10.0.1]")| parse input, """LD "user " SQS:name"""
Matches string enclosed between double-quote characters (ASCII 0x22). Any double quote inside the string must be escaped by a backslash character (ASCII 0x5c).
Use the following expression to parse the value:
DQS:result
For example:
| Description | input (string) | result (string) |
|---|---|---|
Double-quoted string |
|
|
Backslash-escaped double quote |
|
|
Tab inside the quotes |
|
|
Newline inside the quotes |
|
|
Single-quoted input |
|
|
Unclosed quote |
|
|
data record(input = "\"hello world\""),record(input = "\"say \\\"hi\\\"\""),record(input = "\"jdoe\tadmin\""),record(input = "\"line one\nline two\""),record(input = "'hello world'"),record(input = "\"unclosed")| parse input, "DQS:result"
Specify configuration parameters in parentheses after the matcher name: DQS(param=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| Character set name enclosed in single or double quotes (for example |
|
| String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none. |
By default, DQS matches a quoted string of between 1 and 4096 characters, including the two enclosing quote characters. Append a quantifier to override: DQS{min,max}:result.
| Parameter | Type | Description |
|---|---|---|
|
| Minimum number of characters of the quoted string, including the two enclosing quote characters, as a non-negative integer. Parsing fails and the output returns |
|
| Maximum number of characters of the quoted string, including the two enclosing quote characters, greater than or equal to |
The data type of the extracted value is string.
Given the following input:
"Red fox jumps over \"lazy\" dog"
Use the following expression to extract the value:
DQS:result
result (string) |
|---|
|
data record(input = "\"Red fox jumps over \\\"lazy\\\" dog\"")| parse input, "DQS:result"
Given the following input:
input (string) |
|---|
|
Use the following expression to extract the value:
DATA KVP{LD ("SNMPv2-SMI::enterprises." LD):key "\": " DQS:value ',' LF }{1,}:result
DATA skips past non-enterprise fields. Inside the KVP block, LD skips to the literal prefix "SNMPv2-SMI::enterprises.", which is then captured as part of the key along with the OID suffix up to the closing ". DQS extracts the corresponding value.
result (record) |
|---|
|
data record(input = """{"content": "SNMP trap (SNMPv2-SMI::enterprises.1234.3.1.6.17) reported from src:192.168.1.232\n agent:192.168.1.232","status": "NONE","SNMPv2-MIB::snmpTrapEnterprise": ".1.3.6.1.4.1.1234.3.1.6.17","SNMPv2-MIB::snmpTrapOID": ".1.3.6.1.4.1.1234.3.1.6.17","SNMPv2-MIB::sysDescr": "snmpTrap v1.0","SNMPv2-SMI::enterprises.1234.3.1.6.17": "sensor OK","SNMPv2-SMI::enterprises.1234.3.1.6.17.1": "host01.localdomain","SNMPv2-SMI::enterprises.1234.3.1.6.17.9": "sensor stopped","acme.errorcode": "xyz","snmp.version": "2c"}""")| parse input, """DATA KVP{LD ("SNMPv2-SMI::enterprises." LD):key "\": " DQS:value ',' LF }{1,}:result"""
Matches string enclosed between single quotes (ASCII 0x27). Any single quote inside the string must be escaped by single quote character (CSV style).
Use the following expression to parse the value:
CSVSQS:result
For example:
| Description | input (string) | result (string) |
|---|---|---|
Single-quoted string |
|
|
CSV-escaped single quote |
|
|
Tab inside the quotes |
|
|
Newline inside the quotes |
|
|
Double-quoted input |
|
|
Unclosed quote |
|
|
data record(input = "'hello world'"),record(input = "'it''s here'"),record(input = "'jdoe\tadmin'"),record(input = "'line one\nline two'"),record(input = "\"hello world\""),record(input = "'unclosed")| parse input, "CSVSQS:result"
Specify configuration parameters in parentheses after the matcher name: CSVSQS(param=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| Character set name enclosed in single or double quotes (for example |
|
| String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none. |
By default, CSVSQS matches a quoted string of between 1 and 4096 characters, including the two enclosing quote characters. Append a quantifier to override: CSVSQS{min,max}:result.
| Parameter | Type | Description |
|---|---|---|
|
| Minimum number of characters of the quoted string, including the two enclosing quote characters, as a non-negative integer. Parsing fails and the output returns |
|
| Maximum number of characters of the quoted string, including the two enclosing quote characters, greater than or equal to |
The data type of the extracted value is string.
Given the following input:
'Red fox jumps over ''lazy'' dog'
Use the following expression to extract the value:
CSVSQS:result
result (string) |
|---|
|
data record(input = "'Red fox jumps over ''lazy'' dog'")| parse input, "CSVSQS:result"
Matches string enclosed between double-quote characters (ASCII 0x22). Any double quote inside the string must be escaped by double-quote character (CSV style).
Use the following expression to parse the value:
CSVDQS:result
For example:
| Description | input (string) | result (string) |
|---|---|---|
Double-quoted string |
|
|
CSV-escaped double quote |
|
|
Tab inside the quotes |
|
|
Newline inside the quotes |
|
|
Single-quoted input |
|
|
Unclosed quote |
|
|
data record(input = "\"hello world\""),record(input = "\"say \"\"hi\"\"\""),record(input = "\"jdoe\tadmin\""),record(input = "\"line one\nline two\""),record(input = "'hello world'"),record(input = "\"unclosed")| parse input, "CSVDQS:result"
Specify configuration parameters in parentheses after the matcher name: CSVDQS(param=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| Character set name enclosed in single or double quotes (for example |
|
| String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none. |
By default, CSVDQS matches a quoted string of between 1 and 4096 characters, including the two enclosing quote characters. Append a quantifier to override: CSVDQS{min,max}:result.
| Parameter | Type | Description |
|---|---|---|
|
| Minimum number of characters of the quoted string, including the two enclosing quote characters, as a non-negative integer. Parsing fails and the output returns |
|
| Maximum number of characters of the quoted string, including the two enclosing quote characters, greater than or equal to |
The data type of the extracted value is string.
Given the following input:
"Red fox jumps over ""lazy"" dog"
Use the following expression to extract the value:
CSVDQS:result
result (string) |
|---|
|
data record(input = "\"Red fox jumps over \"\"lazy\"\" dog\"")| parse input, "CSVDQS:result"
[ char ... ]
Matches a single character out of several in a defined group. Simply place the characters you want to match between square brackets.
Characters can also be expressed as ranges, for instance [0-9] matches any digit from 0 to 9. Negating is supported by placing a caret ^ or an exclamation mark ! before characters.
In case you want to match a square bracket character, it must be escaped by a preceding backslash character (0x5c ASCII).
Use a quantifier if you want to match more than single characters.
The syntax is compatible with Regular Expression Character Class.
Character group allows matching strings with specific characters (as opposed to LD or DATA which matches any characters).
Use the following expression to parse the value:
[a-z0-9]:result
For example:
| Description | input (string) | result (string) |
|---|---|---|
Lowercase letter |
|
|
Digit |
|
|
Uppercase letter (out of group) |
|
|
Special character |
|
|
data record(input = "a"),record(input = "5"),record(input = "A"),record(input = "@")| parse input, "[a-z0-9]:result"
Specify configuration parameters in parentheses after the character group: [chars](param=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| Character set name enclosed in single or double quotes (for example |
|
| String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none. |
By default, [...] matches exactly one character from the group. Append a quantifier to match multiple characters: [...]{min,max}:result.
| Parameter | Type | Description |
|---|---|---|
|
| Minimum number of characters to match, as a non-negative integer. Parsing fails and the output returns |
|
| Maximum number of characters to match, greater than or equal to |
The data type of the extracted value is string.
Given the following input:
2016-01-03 00:13:28,110.188.4.216,forerequest,200
Use the following expression to extract the value:
TIMESTAMP('yyyy-MM-dd HH:mm:ss'):ts ',' IPADDR:ip ',' [a-z0-9]{4,15}:username ',' LD
ts (timestamp) | ip (string) | username (string) |
|---|---|---|
|
|
|
data record(input = "2016-01-03 00:13:28,110.188.4.216,forerequest,200\n")| parse input, "TIMESTAMP('yyyy-MM-dd HH:mm:ss'):ts ',' IPADDR:ip ',' [a-z0-9]{4,15}:username ',' LD"
Match one or more characters corresponding to any of the characters in the defined group.
You can use either matcher or POSIX notation.
Use the following expression to parse the value:
WORD:result
For example:
| Description | input (string) | result (string) |
|---|---|---|
Word with underscore |
|
|
Word followed by space |
|
|
Alphanumeric |
|
|
Special characters |
|
|
data record(input = "hello_world"),record(input = "hello world"),record(input = "123abc"),record(input = "!@#")| parse input, "WORD:result"
The following classes are available:
| Class | POSIX notation | Description |
|---|---|---|
|
| Matches alphanumeric characters |
|
| Matches alphabetic characters |
|
| Matches space ( |
|
| Matches control characters in ASCII range |
|
| Matches digits |
|
| Matches visible characters in ASCII range |
|
| Matches lowercase letters |
|
| Matches printable characters in ASCII range |
|
| Matches punctuation and symbols |
|
| Matches all whitespace characters: |
|
| Matches all non-whitespace characters |
|
| Matches uppercase letters |
|
| Matches hexadecimal digits |
|
| Matches all ASCII characters |
|
| Matches letters |
|
| Matches any character in ASCII range |
Specify configuration parameters in parentheses after the class name: CLASS(param=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| Character set name enclosed in single or double quotes (for example |
|
| String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none. |
By default, POSIX character classes match between 1 and 4096 characters. Append a quantifier to override: CLASS{min,max}:result.
| Parameter | Type | Description |
|---|---|---|
|
| Minimum number of characters to match, as a non-negative integer. Parsing fails and the output returns |
|
| Maximum number of characters to match, greater than or equal to |
The data type of the extracted value is string.
Given the following input:
2016-01-03 00:13:28,110.188.4.216,forerequest,200
Use the following expression to extract the value:
TIMESTAMP('yyyy-MM-dd HH:mm:ss'):ts ',' IPADDR:ip ',' LOWER{4,15}:username ',' LD
ts (timestamp) | ip (string) | username (string) |
|---|---|---|
|
|
|
data record(input = "2016-01-03 00:13:28,110.188.4.216,forerequest,200\n")| parse input, "TIMESTAMP('yyyy-MM-dd HH:mm:ss'):ts ',' IPADDR:ip ',' LOWER{4,15}:username ',' LD"