Literals are expressed as strings enclosed in single quotes '...' or double quotes "...". They match an exact sequence of characters in the input.
Use the following expression to match a literal value:
'hello'
For example:
| Description | input (string) | result (boolean) |
|---|---|---|
Exact match |
|
|
Different case |
|
|
Different word |
|
|
Literal followed by more text |
|
|
Literal preceded by more text |
|
|
Leading space |
|
|
Trailing space |
|
|
Whitespace only |
|
|
data record(input = "hello"),record(input = "Hello"),record(input = "World"),record(input = "hello world"),record(input = "say hello"),record(input = " hello"),record(input = "hello "),record(input = " ")| fieldsAdd result = matchesPattern(input, "'hello'")
matchesPattern requires the entire input to match the literal—any surrounding characters, including spaces, cause it to return false. To match a literal that appears within a larger value, combine it with other matchers (for example LD 'hello' LD), as shown in the practical example below.
If the literal contains a single quote, enclose it with double quotes, and vice versa. Alternatively, escape the quote with a preceding backslash \ (0x5c ASCII).
Specify configuration parameters in parentheses after the literal: 'text'(param=value).
| parameter | type | Description |
|---|---|---|
|
| Character set name enclosed in single or double quotes (for example |
|
| String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). Default: English |
The data type of the extracted value is string. When used without a :name capture, the literal is only matched and not exported to the output.
The following expression matches one or more occurrences of the character a and captures the result:
'a'+:result
| Description | input (string) | result (string) |
|---|---|---|
Single character |
|
|
Repeated character |
|
|
Non-matching input |
|
|
data record(input = "a"),record(input = "aa"),record(input = "b")| parse input, "'a'+:result"
The following expression checks whether the input consists of one or more occurrences of a:
'a'+
| Description | input (string) | result (boolean) |
|---|---|---|
Single character |
|
|
Repeated character |
|
|
Non-matching input |
|
|
data record(input = "a"),record(input = "aa"),record(input = "b")| fieldsAdd result = matchesPattern(input, "'a'+")
Literals can include escape sequences such as \t (tab) and \n (newline). The escape matches the corresponding control character in the input, and each escape matches only its own character.
The following expression matches the character a, a tab, and the character b:
'a\tb'
| Description | input (string) | result (boolean) |
|---|---|---|
Tab matches the |
|
|
Newline does not match the |
|
|
data record(input = "a\tb"),record(input = "a\nb")| fieldsAdd result = matchesPattern(input, "'a\tb'")
Literals are case-sensitive—the expression matches only if the input contains the exact characters as written. The literal can appear anywhere in a record.
Given the following input:
2024-03-15T08:23:11.000Z host-01 app[123]: level: info Request received
Use the following expression to extract the level value from anywhere in the record:
LD 'level: ' WORD:level
level (string) |
|---|
|
data record(input = "2024-03-15T08:23:11.000Z host-01 app[123]: level: info Request received")| parse input, "LD 'level: ' WORD:level"