Try it free

DPL Lines and Strings

  • Latest Dynatrace
  • Reference

Line Breaks

EOL, LF

Matches the single line feed character (\n, ASCII 0x0A). EOL is used as a line terminator or separator in patterns alongside other matchers.

Use the following expression to match a line separator between two values:

WORD:name EOL WORD:surname

Given the following input:

John\nDoe
name (string)surname (string)

John

Doe

See how to use in DQL
data record(input = "John\nDoe")
| parse input, "WORD:name EOL WORD:surname"

Quantifier

By default, EOL matches exactly one line feed character. Append a quantifier to match multiple consecutive line feeds: EOL{min,max}.

ParameterTypeDescription

min

integer

Minimum number of occurrences, as a non-negative integer. Parsing fails and the output returns null if fewer than min occurrences match. Default: 1.

max

integer

Maximum number of occurrences to match, greater than or equal to min. Default: 1. Maximum: 4096.

Returns

EOL is typically used without a capture name as a line terminator or separator. When captured (EOL:result), the data type of the extracted value is string.

Practical example

Example: Parse per-line percentage values from a multiline tabular report

Given the following input:

input (string)
Status Name Type Extent Man Initial Extent Size (M) Used (MB) Used %
--------- -------------- ---------- --------------- ------------------ ------------ ------------ --------------
ONLINE SAMPLE_INDEX_X GROUP_ONE EXT_A 65536 908,304.000 905,890.125 99.73
ONLINE SAMPLE_INDEX_X GROUP_ONE EXT_A 65536 908,304.000 905,890.125 99.72
ONLINE SAMPLE_INDEX_X GROUP_ONE EXT_A 65536 908,304.000 905,890.125 99.71
ONLINE SAMPLE_INDEX_X GROUP_ONE EXT_A 65536 908,304.000 905,890.125 99.79

Use the following expression to extract the value:

ARRAY{ DATA ([0-9]{1,2} '.' [0-9]{2} >> (EOL|EOS)):i }{1,}:result

The >> lookahead anchors the number pattern to the position just before a line end or the end of the input, so DATA skips each line's leading columns and only the trailing Used % value is captured per line. Header and separator lines contain no such number and are consumed by DATA without producing an array element. The (EOL|EOS) alternation also captures the value on the last line when the input has no trailing newline.

result (array)

["99.73", "99.72", "99.71", "99.79"]

See how to use in DQL
data record(input = """
Status Name Type Extent Man Initial Extent Size (M) Used (MB) Used %
--------- -------------- ---------- --------------- ------------------ ------------ ------------ --------------
ONLINE SAMPLE_INDEX_X GROUP_ONE EXT_A 65536 908,304.000 905,890.125 99.73
ONLINE SAMPLE_INDEX_X GROUP_ONE EXT_A 65536 908,304.000 905,890.125 99.72
ONLINE SAMPLE_INDEX_X GROUP_ONE EXT_A 65536 908,304.000 905,890.125 99.71
ONLINE SAMPLE_INDEX_X GROUP_ONE EXT_A 65536 908,304.000 905,890.125 99.79
""")
| parse input, "ARRAY{ DATA ([0-9]{1,2} '.' [0-9]{2} >> (EOL|EOS)):i }{1,}:result"
| fields result

CR

Matches the single carriage return character (CR, \r, ASCII 0x0D). CR is used as a line terminator or separator in patterns alongside other matchers.

Use the following expression to match a line separator between two values:

WORD:name CR WORD:surname

Given the following input:

John\rDoe
name (string)surname (string)

John

Doe

See how to use in DQL
data record(input = "John\rDoe")
| parse input, "WORD:name CR WORD:surname"

Quantifier

By default, CR matches exactly one carriage return character. Append a quantifier to match multiple consecutive carriage returns: CR{min,max}.

ParameterTypeDescription

min

integer

Minimum number of occurrences, as a non-negative integer. Parsing fails and the output returns null if fewer than min occurrences match. Default: 1.

max

integer

Maximum number of occurrences to match, greater than or equal to min. Default: 1. Maximum: 1000000.

Returns

CR is typically used without a capture name as a line terminator or separator. When captured (CR:result), the data type of the extracted value is string.

Practical example

Example: Parse CR-delimited log messages into an array

Given the following input (CR-only line endings, as produced by legacy Mac OS and some embedded systems):

ERROR: disk full\rWARN: low memory\rINFO: backup complete

Use the following expression to extract the value:

ARRAY{LD:item (CR|EOS)}{1,}:result

(CR|EOS) handles both the CR between records and the end-of-string after the last record, so no trailing CR is required on the final line.

result (array)

["ERROR: disk full", "WARN: low memory", "INFO: backup complete"]

See how to use in DQL
data record(input = "ERROR: disk full\rWARN: low memory\rINFO: backup complete")
| parse input, "ARRAY{LD:item (CR|EOS)}{1,}:result"
| fields result

EOLWIN

Matches the Windows line ending sequence (CRLF, \r\n, ASCII 0x0D 0x0A). EOLWIN is used as a line terminator or separator in patterns alongside other matchers.

Use the following expression to match a Windows line separator between two values:

WORD:name EOLWIN WORD:surname

Given the following input:

John\r\nDoe
name (string)surname (string)

John

Doe

See how to use in DQL
data record(input = "John\r\nDoe")
| parse input, "WORD:name EOLWIN WORD:surname"

Quantifier

By default, EOLWIN matches exactly one Windows line ending sequence. Append a quantifier to match multiple consecutive sequences: EOLWIN{min,max}.

ParameterTypeDescription

min

integer

Minimum number of occurrences, as a non-negative integer. Parsing fails and the output returns null if fewer than min occurrences match. Default: 1.

max

integer

Maximum number of occurrences to match, greater than or equal to min. Default: 1. Maximum: 4096.

Returns

EOLWIN is typically used without a capture name as a line terminator or separator. When captured (EOLWIN:result), the data type of the extracted value is string.

Practical example

Example: Parse user and domain from a Windows security log

Given the following input (Windows Event ID 4625—failed logon):

An account failed to log on.\r\n\r\nFailed:\r\n\tSecurity ID:\t\tNULL SID\r\n\tAccount Name:\t\tjdoe\r\n\tAccount Domain:\t\tCORPDOMAIN\r\n\tLogon Type:\t\t3\r\n\r\nFailure Information:\r\n\tFailure Reason:\t\tUnknown user name or bad password.\r\n\tStatus:\t\t\t0xC000006D\r\n\tSub Status:\t\t0xC0000064\r\n

Use the following expression to extract the value:

DATA 'Account Name:' BLANK LD?:'login.attempt.user' EOLWIN DATA 'Account Domain:' BLANK LD?:'login.attempt.domain'
login.attempt.user (string)login.attempt.domain (string)

jdoe

CORPDOMAIN

See how to use in DQL
data record(input = "An account failed to log on.\r\n\r\nFailed:\r\n\tSecurity ID:\t\tNULL SID\r\n\tAccount Name:\t\tjdoe\r\n\tAccount Domain:\t\tCORPDOMAIN\r\n\tLogon Type:\t\t3\r\n\r\nFailure Information:\r\n\tFailure Reason:\t\tUnknown user name or bad password.\r\n\tStatus:\t\t\t0xC000006D\r\n\tSub Status:\t\t0xC0000064\r\n")
| parse input, "DATA 'Account Name:' BLANK LD?:'login.attempt.user' EOLWIN DATA 'Account Domain:' BLANK LD?:'login.attempt.domain'"

Line Data

LD, LDATA

Matches any characters until the next non-optional matcher in the scope of a line.

LD must always be followed by a non-optional matcher expression.

Use the following expression to parse the value:

LD:result

For example:

Descriptioninput (string)result (string)

Single-line text

Red fox jumps

Red fox jumps

Text containing a newline

line one\nline two

line one

See how to use in DQL
data record(input = "Red fox jumps"),
record(input = "line one\nline two")
| parse input, "LD:result"

Configuration

Specify configuration parameters in parentheses after the matcher name: LD(param=value):result.

ParameterTypeDescription

charset

string

Character set name enclosed in single or double quotes (for example charset="ISO-8859-1"). Default: none.

locale

string

String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none.

Quantifier

By default, LD matches between 1 and 4096 characters. Append a quantifier to override: LD{min,max}:result.

ParameterTypeDescription

min

integer

Minimum number of characters to match, as a non-negative integer. Parsing fails and the output returns null if fewer than min characters match. Default: 1.

max

integer

Maximum number of characters to match, greater than or equal to min. Default: 4096. Maximum: 16000000.

Returns

The data type of the extracted value is string.

Basic example

Example: Parse two fields from a newline-separated value

Given the following input:

Red fox jumps\nover lazy dog

Use the following expression to extract the value:

LD:first EOL LD:second
first (string)second (string)

Red fox jumps

over lazy dog

See how to use in DQL
data record(input = "Red fox jumps\nover lazy dog\n")
| parse input, "LD:first EOL LD:second"

Practical example

Example: Parse a username from a CSV access log

Given the following input:

2016-01-03 00:13:28,110.188.4.216,forerequest,200

Use the following expression to extract the value:

TIMESTAMP('yyyy-MM-dd HH:mm:ss'):ts ',' IPADDR:ip ',' LD:username ',' LD
ts (timestamp)ip (string)username (string)

2016-01-03T00:13:28.000000000Z

110.188.4.216

forerequest

See how to use in DQL
data record(input = "2016-01-03 00:13:28,110.188.4.216,forerequest,200\n")
| parse input, "TIMESTAMP('yyyy-MM-dd HH:mm:ss'):ts ',' IPADDR:ip ',' LD:username ',' LD"

Multiline Data

DATA

Matches any characters until the next non-optional matcher of pattern expression.

DATA must always be followed by a non-optional matcher expression.

Use the following expression to parse the value:

DATA:result

For example:

Descriptioninput (string)result (string)

Single-line text

Red fox jumps

Red fox jumps

Text containing a newline

line one\nline two

line one\nline two

See how to use in DQL
data record(input = "Red fox jumps"),
record(input = "line one\nline two")
| parse input, "DATA:result"

Configuration

Specify configuration parameters in parentheses after the matcher name: DATA(param=value):result.

ParameterTypeDescription

charset

string

Character set name enclosed in single or double quotes (for example charset="ISO-8859-1"). Default: none.

locale

string

String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none.

Quantifier

By default, DATA matches between 1 and 4096 characters. Append a quantifier to override: DATA{min,max}:result.

ParameterTypeDescription

min

integer

Minimum number of characters to match, as a non-negative integer. Parsing fails and the output returns null if fewer than min characters match. Default: 1.

max

integer

Maximum number of characters to match, greater than or equal to min. Default: 4096. Maximum: 16000000.

Returns

The data type of the extracted value is string.

Practical example

Example: Parse the first record from a concatenated log stream

Given the following input:

2015.10.03 16:32:51.371 +0000 ERROR com.dt.webconsole.jsp.data.SQLTimeSeriesCache -- SQLTimeSeries remote fetch failed org.postgresql.util.PSQLException: Connection refused. Check that the hostname and port are correct and that the postmaster is accepting TCP/IP connections. at org.postgresql.core.ConnectionFactory.openConnection(ConnectionFactory.java:66) 2015-10-03 19:33:47.422 +0000 WARN main com.dt.wgui.WGUIMain Log processing started in /Users/user/dt, listening http://localhost:8390/, pid: 11364@abcdef

Use the following expression to extract the value:

DATA:result TIMESTAMP('yyyy-MM-dd HH:mm:ss.SSS Z'):next_ts

DATA matches any content, stopping at the first position where TIMESTAMP matches. The first record is captured in result, and the timestamp that starts the second record is captured in next_ts.

result (string)next_ts (timestamp)

2015.10.03 16:32:51.371 +0000 ERROR com.dt.webconsole.jsp.data.SQLTimeSeriesCache -- SQLTimeSeries remote fetch failed org.postgresql.util.PSQLException: Connection refused. Check that the hostname and port are correct and that the postmaster is accepting TCP/IP connections. at org.postgresql.core.ConnectionFactory.openConnection(ConnectionFactory.java:66)␣

2015-10-03T19:33:47.422Z

See how to use in DQL
data record(input = "2015.10.03 16:32:51.371 +0000 ERROR com.dt.webconsole.jsp.data.SQLTimeSeriesCache -- SQLTimeSeries remote fetch failed org.postgresql.util.PSQLException: Connection refused. Check that the hostname and port are correct and that the postmaster is accepting TCP/IP connections. at org.postgresql.core.ConnectionFactory.openConnection(ConnectionFactory.java:66) 2015-10-03 19:33:47.422 +0000 WARN main com.dt.wgui.WGUIMain Log processing started in /Users/user/dt, listening http://localhost:8390/, pid: 11364@abcdef")
| parse input, """DATA:result TIMESTAMP('yyyy-MM-dd HH:mm:ss.SSS Z'):next_ts"""

Quoted Strings

SQS

Matches string enclosed between single quotes (ASCII 0x27). Any single quote inside the string must be escaped by backslash character \.

Use the following expression to parse the value:

SQS:result

For example:

Descriptioninput (string)result (string)

Single-quoted string

'hello world'

hello world

Backslash-escaped single quote

'it\'s here'

it's here

Tab inside the quotes

'jdoe\tadmin'

jdoe\tadmin

Newline inside the quotes

'line one\nline two'

line one\nline two

Double-quoted input

"hello world"

null

Unclosed quote

'unclosed

null

See how to use in DQL
data record(input = "'hello world'"),
record(input = "'it\\'s here'"),
record(input = "'jdoe\tadmin'"),
record(input = "'line one\nline two'"),
record(input = "\"hello world\""),
record(input = "'unclosed")
| parse input, "SQS:result"

Configuration

Specify configuration parameters in parentheses after the matcher name: SQS(param=value):result.

ParameterTypeDescription

charset

string

Character set name enclosed in single or double quotes (for example charset="ISO-8859-1"). Default: none.

locale

string

String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none.

Quantifier

By default, SQS matches a quoted string of between 1 and 4096 characters, including the two enclosing quote characters. Append a quantifier to override: SQS{min,max}:result.

ParameterTypeDescription

min

integer

Minimum number of characters of the quoted string, including the two enclosing quote characters, as a non-negative integer. Parsing fails and the output returns null if fewer than min characters match. Default: 1.

max

integer

Maximum number of characters of the quoted string, including the two enclosing quote characters, greater than or equal to min. Default: 4096. Maximum: 1000000.

Returns

The data type of the extracted value is string.

Basic example

Example: Parse the content of a backslash-escaped single-quoted string

Given the following input:

'Homer said: d\'oh!'

Use the following expression to extract the value:

SQS:result
result (string)

Homer said: d'oh!

See how to use in DQL
data record(input = "'Homer said: d\\'oh!'")
| parse input, "SQS:result"

Practical example

Example: Parse a username from a failed login log entry

Given the following input:

2026-02-24 05:18:34.1541876 Login failed for user 'jdoe'. Reason: Password did not match that for the login provided. [CLIENT: 192.10.0.1]

Use the following expression to extract the value:

LD "user " SQS:name
name (string)

jdoe

See how to use in DQL
data record(input = "2026-02-24 05:18:34.1541876\tLogin failed for user 'jdoe'. Reason: Password did not match that for the login provided. [CLIENT: 192.10.0.1]")
| parse input, """LD "user " SQS:name"""

DQS

Matches string enclosed between double-quote characters (ASCII 0x22). Any double quote inside the string must be escaped by a backslash character (ASCII 0x5c).

Use the following expression to parse the value:

DQS:result

For example:

Descriptioninput (string)result (string)

Double-quoted string

"hello world"

hello world

Backslash-escaped double quote

"say \"hi\""

say "hi"

Tab inside the quotes

"jdoe\tadmin"

jdoe\tadmin

Newline inside the quotes

"line one\nline two"

line one\nline two

Single-quoted input

'hello world'

null

Unclosed quote

"unclosed

null

See how to use in DQL
data record(input = "\"hello world\""),
record(input = "\"say \\\"hi\\\"\""),
record(input = "\"jdoe\tadmin\""),
record(input = "\"line one\nline two\""),
record(input = "'hello world'"),
record(input = "\"unclosed")
| parse input, "DQS:result"

Configuration

Specify configuration parameters in parentheses after the matcher name: DQS(param=value):result.

ParameterTypeDescription

charset

string

Character set name enclosed in single or double quotes (for example charset="ISO-8859-1"). Default: none.

locale

string

String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none.

Quantifier

By default, DQS matches a quoted string of between 1 and 4096 characters, including the two enclosing quote characters. Append a quantifier to override: DQS{min,max}:result.

ParameterTypeDescription

min

integer

Minimum number of characters of the quoted string, including the two enclosing quote characters, as a non-negative integer. Parsing fails and the output returns null if fewer than min characters match. Default: 1.

max

integer

Maximum number of characters of the quoted string, including the two enclosing quote characters, greater than or equal to min. Default: 4096. Maximum: 1000000.

Returns

The data type of the extracted value is string.

Basic example

Example: Parse the content of a backslash-escaped double-quoted string

Given the following input:

"Red fox jumps over \"lazy\" dog"

Use the following expression to extract the value:

DQS:result
result (string)

Red fox jumps over "lazy" dog

See how to use in DQL
data record(input = "\"Red fox jumps over \\\"lazy\\\" dog\"")
| parse input, "DQS:result"

Practical example

Example: Parse SNMP enterprise OID values from a JSON payload

Given the following input:

input (string)
{
"content": "SNMP trap (SNMPv2-SMI::enterprises.1234.3.1.6.17) reported from src:192.168.1.232\n agent:192.168.1.232",
"status": "NONE",
"SNMPv2-MIB::snmpTrapEnterprise": ".1.3.6.1.4.1.1234.3.1.6.17",
"SNMPv2-MIB::snmpTrapOID": ".1.3.6.1.4.1.1234.3.1.6.17",
"SNMPv2-MIB::sysDescr": "snmpTrap v1.0",
"SNMPv2-SMI::enterprises.1234.3.1.6.17": "sensor OK",
"SNMPv2-SMI::enterprises.1234.3.1.6.17.1": "host01.localdomain",
"SNMPv2-SMI::enterprises.1234.3.1.6.17.9": "sensor stopped",
"acme.errorcode": "xyz",
"snmp.version": "2c"
}

Use the following expression to extract the value:

DATA KVP{LD ("SNMPv2-SMI::enterprises." LD):key "\": " DQS:value ',' LF }{1,}:result

DATA skips past non-enterprise fields. Inside the KVP block, LD skips to the literal prefix "SNMPv2-SMI::enterprises.", which is then captured as part of the key along with the OID suffix up to the closing ". DQS extracts the corresponding value.

result (record)

{"SNMPv2-SMI::enterprises.1234.3.1.6.17": "sensor OK", "SNMPv2-SMI::enterprises.1234.3.1.6.17.1": "host01.localdomain", "SNMPv2-SMI::enterprises.1234.3.1.6.17.9": "sensor stopped"}

See how to use in DQL
data record(input = """{
"content": "SNMP trap (SNMPv2-SMI::enterprises.1234.3.1.6.17) reported from src:192.168.1.232\n agent:192.168.1.232",
"status": "NONE",
"SNMPv2-MIB::snmpTrapEnterprise": ".1.3.6.1.4.1.1234.3.1.6.17",
"SNMPv2-MIB::snmpTrapOID": ".1.3.6.1.4.1.1234.3.1.6.17",
"SNMPv2-MIB::sysDescr": "snmpTrap v1.0",
"SNMPv2-SMI::enterprises.1234.3.1.6.17": "sensor OK",
"SNMPv2-SMI::enterprises.1234.3.1.6.17.1": "host01.localdomain",
"SNMPv2-SMI::enterprises.1234.3.1.6.17.9": "sensor stopped",
"acme.errorcode": "xyz",
"snmp.version": "2c"
}""")
| parse input, """DATA KVP{LD ("SNMPv2-SMI::enterprises." LD):key "\": " DQS:value ',' LF }{1,}:result"""

CSVSQS

Matches string enclosed between single quotes (ASCII 0x27). Any single quote inside the string must be escaped by single quote character (CSV style).

Use the following expression to parse the value:

CSVSQS:result

For example:

Descriptioninput (string)result (string)

Single-quoted string

'hello world'

hello world

CSV-escaped single quote

'it''s here'

it's here

Tab inside the quotes

'jdoe\tadmin'

jdoe\tadmin

Newline inside the quotes

'line one\nline two'

line one\nline two

Double-quoted input

"hello world"

null

Unclosed quote

'unclosed

null

See how to use in DQL
data record(input = "'hello world'"),
record(input = "'it''s here'"),
record(input = "'jdoe\tadmin'"),
record(input = "'line one\nline two'"),
record(input = "\"hello world\""),
record(input = "'unclosed")
| parse input, "CSVSQS:result"

Configuration

Specify configuration parameters in parentheses after the matcher name: CSVSQS(param=value):result.

ParameterTypeDescription

charset

string

Character set name enclosed in single or double quotes (for example charset="ISO-8859-1"). Default: none.

locale

string

String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none.

Quantifier

By default, CSVSQS matches a quoted string of between 1 and 4096 characters, including the two enclosing quote characters. Append a quantifier to override: CSVSQS{min,max}:result.

ParameterTypeDescription

min

integer

Minimum number of characters of the quoted string, including the two enclosing quote characters, as a non-negative integer. Parsing fails and the output returns null if fewer than min characters match. Default: 1.

max

integer

Maximum number of characters of the quoted string, including the two enclosing quote characters, greater than or equal to min. Default: 4096. Maximum: 1000000.

Returns

The data type of the extracted value is string.

Basic example

Example: Parse the content of a CSV single-quoted string

Given the following input:

'Red fox jumps over ''lazy'' dog'

Use the following expression to extract the value:

CSVSQS:result
result (string)

Red fox jumps over 'lazy' dog

See how to use in DQL
data record(input = "'Red fox jumps over ''lazy'' dog'")
| parse input, "CSVSQS:result"

CSVDQS

Matches string enclosed between double-quote characters (ASCII 0x22). Any double quote inside the string must be escaped by double-quote character (CSV style).

Use the following expression to parse the value:

CSVDQS:result

For example:

Descriptioninput (string)result (string)

Double-quoted string

"hello world"

hello world

CSV-escaped double quote

"say ""hi"""

say "hi"

Tab inside the quotes

"jdoe\tadmin"

jdoe\tadmin

Newline inside the quotes

"line one\nline two"

line one\nline two

Single-quoted input

'hello world'

null

Unclosed quote

"unclosed

null

See how to use in DQL
data record(input = "\"hello world\""),
record(input = "\"say \"\"hi\"\"\""),
record(input = "\"jdoe\tadmin\""),
record(input = "\"line one\nline two\""),
record(input = "'hello world'"),
record(input = "\"unclosed")
| parse input, "CSVDQS:result"

Configuration

Specify configuration parameters in parentheses after the matcher name: CSVDQS(param=value):result.

ParameterTypeDescription

charset

string

Character set name enclosed in single or double quotes (for example charset="ISO-8859-1"). Default: none.

locale

string

String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none.

Quantifier

By default, CSVDQS matches a quoted string of between 1 and 4096 characters, including the two enclosing quote characters. Append a quantifier to override: CSVDQS{min,max}:result.

ParameterTypeDescription

min

integer

Minimum number of characters of the quoted string, including the two enclosing quote characters, as a non-negative integer. Parsing fails and the output returns null if fewer than min characters match. Default: 1.

max

integer

Maximum number of characters of the quoted string, including the two enclosing quote characters, greater than or equal to min. Default: 4096. Maximum: 1000000.

Returns

The data type of the extracted value is string.

Basic example

Example: Parse the content of a CSV double-quoted string

Given the following input:

"Red fox jumps over ""lazy"" dog"

Use the following expression to extract the value:

CSVDQS:result
result (string)

Red fox jumps over "lazy" dog

See how to use in DQL
data record(input = "\"Red fox jumps over \"\"lazy\"\" dog\"")
| parse input, "CSVDQS:result"

Character Group

[ char ... ]

Matches a single character out of several in a defined group. Simply place the characters you want to match between square brackets.

Characters can also be expressed as ranges, for instance [0-9] matches any digit from 0 to 9. Negating is supported by placing a caret ^ or an exclamation mark ! before characters.

In case you want to match a square bracket character, it must be escaped by a preceding backslash character (0x5c ASCII).

Use a quantifier if you want to match more than single characters.

The syntax is compatible with Regular Expression Character Class.

Character group allows matching strings with specific characters (as opposed to LD or DATA which matches any characters).

Use the following expression to parse the value:

[a-z0-9]:result

For example:

Descriptioninput (string)result (string)

Lowercase letter

a

a

Digit

5

5

Uppercase letter (out of group)

A

null

Special character

@

null

See how to use in DQL
data record(input = "a"),
record(input = "5"),
record(input = "A"),
record(input = "@")
| parse input, "[a-z0-9]:result"

Configuration

Specify configuration parameters in parentheses after the character group: [chars](param=value):result.

ParameterTypeDescription

charset

string

Character set name enclosed in single or double quotes (for example charset="ISO-8859-1"). Default: none.

locale

string

String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none.

Quantifier

By default, [...] matches exactly one character from the group. Append a quantifier to match multiple characters: [...]{min,max}:result.

ParameterTypeDescription

min

integer

Minimum number of characters to match, as a non-negative integer. Parsing fails and the output returns null if fewer than min characters match. Default: 1.

max

integer

Maximum number of characters to match, greater than or equal to min. Default: 1. Maximum: 1000000.

Returns

The data type of the extracted value is string.

Basic example

Example: Parse a username from a CSV access log

Given the following input:

2016-01-03 00:13:28,110.188.4.216,forerequest,200

Use the following expression to extract the value:

TIMESTAMP('yyyy-MM-dd HH:mm:ss'):ts ',' IPADDR:ip ',' [a-z0-9]{4,15}:username ',' LD
ts (timestamp)ip (string)username (string)

2016-01-03T00:13:28.000000000Z

110.188.4.216

forerequest

See how to use in DQL
data record(input = "2016-01-03 00:13:28,110.188.4.216,forerequest,200\n")
| parse input, "TIMESTAMP('yyyy-MM-dd HH:mm:ss'):ts ',' IPADDR:ip ',' [a-z0-9]{4,15}:username ',' LD"

POSIX Character Classes

Match one or more characters corresponding to any of the characters in the defined group.

You can use either matcher or POSIX notation.

Use the following expression to parse the value:

WORD:result

For example:

Descriptioninput (string)result (string)

Word with underscore

hello_world

hello_world

Word followed by space

hello world

hello

Alphanumeric

123abc

123abc

Special characters

!@#

null

See how to use in DQL
data record(input = "hello_world"),
record(input = "hello world"),
record(input = "123abc"),
record(input = "!@#")
| parse input, "WORD:result"

The following classes are available:

ClassPOSIX notationDescription

ALNUM

[:alnum:]

Matches alphanumeric characters a-z, A-Z, 0-9

ALPHA

[:alpha:]

Matches alphabetic characters a-z, A-Z

BLANK

[:blank:]

Matches space (0x20) and tab (0x09) characters

CNTRL

[:cntrl:]

Matches control characters in ASCII range 0x01–0x1F, 0x7F

DIGIT

[:digit:]

Matches digits 0–9

GRAPH

[:graph:]

Matches visible characters in ASCII range 0x21–0x7E

LOWER

[:lower:]

Matches lowercase letters a-z

PRINT

[:print:]

Matches printable characters in ASCII range 0x20–0x7E

PUNCT

[:punct:]

Matches punctuation and symbols !"#$%&'()*+,\-./:;<=>?@[]^_`{|}~

SPACE

[:space:]

Matches all whitespace characters: 0x20, 0x09, 0x0A, 0x0B, 0x0C, 0x0D

NSPACE

[!:space:]

Matches all non-whitespace characters

UPPER

[:upper:]

Matches uppercase letters A-Z

XDIGIT

[:xdigit:]

Matches hexadecimal digits 0-9, a-f, A-F

ASCII

[:ascii:]

Matches all ASCII characters 0x00–0x7F

WORD

[:word:]

Matches letters a-z, A-Z, digits 0-9, and underscore _

[:any:]

[:any:]

Matches any character in ASCII range 0x00–0xFF

Configuration

Specify configuration parameters in parentheses after the class name: CLASS(param=value):result.

ParameterTypeDescription

charset

string

Character set name enclosed in single or double quotes (for example charset="ISO-8859-1"). Default: none.

locale

string

String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none.

Quantifier

By default, POSIX character classes match between 1 and 4096 characters. Append a quantifier to override: CLASS{min,max}:result.

ParameterTypeDescription

min

integer

Minimum number of characters to match, as a non-negative integer. Parsing fails and the output returns null if fewer than min characters match. Default: 1.

max

integer

Maximum number of characters to match, greater than or equal to min. Default: 4096. Maximum: 1000000.

Returns

The data type of the extracted value is string.

Basic example

Example: Parse a lowercase username from a CSV access log

Given the following input:

2016-01-03 00:13:28,110.188.4.216,forerequest,200

Use the following expression to extract the value:

TIMESTAMP('yyyy-MM-dd HH:mm:ss'):ts ',' IPADDR:ip ',' LOWER{4,15}:username ',' LD
ts (timestamp)ip (string)username (string)

2016-01-03T00:13:28.000000000Z

110.188.4.216

forerequest

See how to use in DQL
data record(input = "2016-01-03 00:13:28,110.188.4.216,forerequest,200\n")
| parse input, "TIMESTAMP('yyyy-MM-dd HH:mm:ss'):ts ',' IPADDR:ip ',' LOWER{4,15}:username ',' LD"
Related tags
Dynatrace Platform