This page documents the DPL matchers for numeric data. Matchers in the same family accept the same input but differ in output type or supported range—the tables below compare the related matchers side by side.
| Description | input (string) | INT (long) | LONG (long) |
|---|---|---|---|
Negative |
|
|
|
Decimal |
|
|
|
Comma-separated |
|
|
|
Hexadecimal |
|
|
|
INT maximum |
|
|
|
INT maximum + 1 |
|
|
|
LONG maximum |
|
|
|
LONG maximum + 1 |
|
|
|
Whitespace |
|
|
|
data record(input = "-10"),record(input = "2.5"),record(input = "3,6"),record(input = "0xa01F"),record(input = "2147483647"),record(input = "2147483648"),record(input = "9223372036854775807"),record(input = "9223372036854775808"),record(input = " ")| parse input, "INT:int"| parse input, "LONG:long"
| Description | input (string) | HEXINT (long) | HEXLONG (long) |
|---|---|---|---|
Prefixed with |
|
|
|
Prefixed with |
|
|
|
Prefixed with |
|
|
|
Plain hex digits |
|
|
|
Above INT range |
|
|
|
LONG maximum |
|
|
|
LONG maximum + 1 |
|
|
|
Non-hex text |
|
|
|
Whitespace |
|
|
|
data record(input = "0xa01F"),record(input = "x3"),record(input = "-xFE"),record(input = "10fE"),record(input = "0xFFFFFFFF"),record(input = "0x7FFFFFFFFFFFFFFF"),record(input = "0x8000000000000000"),record(input = "word"),record(input = " ")| parse input, "HEXINT:hexint"| parse input, "HEXLONG:hexlong"
Matches case-insensitive strings true and false.
Use the following pattern to parse boolean values:
BOOLEAN:result
For example, parsing boolean strings in different cases:
| Description | input (string) | result (boolean) |
|---|---|---|
Lowercase |
|
|
Uppercase |
|
|
Mixed case |
|
|
Numeric, not a boolean |
|
|
Word, not a boolean |
|
|
Whitespace |
|
|
data record(input = "true"),record(input = "FALSE"),record(input = "TrUe"),record(input = "1"),record(input = "yes"),record(input = " ")| parse input, "BOOLEAN:result"
The data type of the extracted value is boolean.
Given the following input:
debug_enabled=true
Use the following pattern to extract the boolean value:
'debug_enabled=' BOOLEAN:result
result (boolean) |
|---|
|
data record(input = "debug_enabled=true")| parse input, "'debug_enabled=' BOOLEAN:result"
Given the following input:
debug_enabled=maybe
Use the following pattern to check whether the field contains a valid boolean:
'debug_enabled=' BOOLEAN
We get the following output:
result (boolean) |
|---|
|
data record(input = "debug_enabled=maybe")| fieldsAdd result = matchesPattern(input, "'debug_enabled=' BOOLEAN")
Matches floating point numbers in the form of [+|-]?[0-9]+[.0-9]* (dot "." separated) or [+|-]?[0-9]+[E|e0-9]* (scientific notation).
Use the following pattern to parse float values:
FLOAT:result
For example, parsing float values in different formats:
| Description | input (string) | result (double) |
|---|---|---|
Scientific notation |
|
|
Integer |
|
|
Dot-decimal value |
|
|
Comma-decimal value |
|
|
Whitespace |
|
|
data record(input = "3e0"),record(input = "1"),record(input = "0.1"),record(input = "9,3"),record(input = " ")| parse input, "FLOAT:result"
Specify configuration parameters in parentheses after the matcher name: FLOAT(min=value, max=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| The minimum of parsed value. If the value is less than this the parsing fails and the output is set to |
|
| The maximum of parsed value. If the value is greater than this the parsing fails and the output is set to |
The data type of the extracted value is double.
The following pattern checks if a float value is between 1 and 3:
FLOAT(min=1, max=3)
| Description | input (string) | result (boolean) |
|---|---|---|
In range |
|
|
At maximum |
|
|
Below minimum |
|
|
Above maximum |
|
|
data record(input = "2.5"),record(input = "3.0"),record(input = "0.5"),record(input = "3.5")| fieldsAdd result = matchesPattern(input, "FLOAT(min=1, max=3)")
Given the following input:
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:123.0) Gecko/20100101 Firefox/123.0
Use the following pattern to extract the Mozilla and Firefox versions:
'Mozilla/' FLOAT:mozilla DATA 'Firefox/' FLOAT:firefox
mozilla (double) | firefox (double) |
|---|---|
|
|
data record(input = "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:123.0) Gecko/20100101 Firefox/123.0")| parse input, """'Mozilla/' FLOAT:mozilla DATA 'Firefox/' FLOAT:firefox"""
Given the following input:
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:123.0) Gecko/20100101 Firefox/123.0
Use the following pattern to check whether the Firefox version is 148 or higher:
LD 'Firefox/' FLOAT(min=148)
We get the following output:
result (boolean) |
|---|
|
data record(input = "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:123.0) Gecko/20100101 Firefox/123.0")| fieldsAdd result = matchesPattern(input, """LD 'Firefox/' FLOAT(min=148)""")
Same as FLOAT, but uses comma , as decimal separator: [+|-]?[0-9]+[,0-9]* or [+|-]?[0-9]+[E|e0-9]*.
Use the following pattern to parse comma-decimal float values:
CFLOAT:result
For example, parsing comma-decimal float values:
| Description | input (string) | result (double) |
|---|---|---|
Comma-decimal value |
|
|
Dot-decimal value |
|
|
Scientific notation |
|
|
Integer |
|
|
Whitespace |
|
|
data record(input = "1,5"),record(input = "1.5"),record(input = "3e0"),record(input = "1"),record(input = " ")| parse input, "CFLOAT:result"
Specify configuration parameters in parentheses after the matcher name: CFLOAT(min=value, max=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| The minimum of parsed value. If the value is less than this the parsing fails and the output is set to |
|
| The maximum of parsed value. If the value is greater than this the parsing fails and the output is set to |
The data type of the extracted value is double.
The following pattern checks if a comma-decimal value is between 1 and 5:
CFLOAT(min=1, max=5)
| Description | input (string) | result (boolean) |
|---|---|---|
In range |
|
|
At maximum |
|
|
Below minimum |
|
|
Above maximum |
|
|
data record(input = "2,5"),record(input = "5,0"),record(input = "0,5"),record(input = "6,0")| fieldsAdd result = matchesPattern(input, "CFLOAT(min=1, max=5)")
Matches floating point numbers in the form of [+|-]?[0-9]+[.0-9]* (dot "." separated) or [+|-]?[0-9]+[E|e0-9]* (scientific notation).
Use the following pattern to parse double values:
DOUBLE:result
For example, parsing double values in different formats:
| Description | input (string) | result (double) |
|---|---|---|
Scientific notation |
|
|
Integer |
|
|
Dot-decimal value |
|
|
Comma-decimal value |
|
|
Whitespace |
|
|
data record(input = "3e0"),record(input = "1"),record(input = "0.15"),record(input = "0,15"),record(input = " ")| parse input, "DOUBLE:result"
Specify configuration parameters in parentheses after the matcher name: DOUBLE(min=value, max=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| The minimum of parsed value. If the value is less than this the parsing fails and the output is set to |
|
| The maximum of parsed value. If the value is greater than this the parsing fails and the output is set to |
The data type of the extracted value is double.
The following pattern checks if a double value is between 0 and 1:
DOUBLE(min=0, max=1)
| Description | input (string) | result (boolean) |
|---|---|---|
In range |
|
|
At maximum |
|
|
Above maximum |
|
|
Whitespace |
|
|
data record(input = "0.15"),record(input = "1.0"),record(input = "1.5"),record(input = " ")| fieldsAdd result = matchesPattern(input, "DOUBLE(min=0, max=1)")
Given the following input:
metrics cpu.load=0.85 mem.used=2.5
Use the following pattern to extract the CPU load and memory usage:
LD 'cpu.load=' DOUBLE:cpu_load SPACE 'mem.used=' DOUBLE:mem_used
cpu_load (double) | mem_used (double) |
|---|---|
|
|
data record(input = "metrics cpu.load=0.85 mem.used=2.5")| parse input, "LD 'cpu.load=' DOUBLE:cpu_load SPACE 'mem.used=' DOUBLE:mem_used"
Same as DOUBLE, but uses comma , as decimal separator: [+|-]?[0-9]+[,0-9]* or [+|-]?[0-9]+[E|e0-9]*.
Use the following pattern to parse comma-decimal double values:
CDOUBLE:result
For example, parsing comma-decimal double values:
| Description | input (string) | result (double) |
|---|---|---|
Comma-decimal value |
|
|
Dot-decimal value |
|
|
Scientific notation |
|
|
Integer |
|
|
Whitespace |
|
|
data record(input = "1,5"),record(input = "1.5"),record(input = "3e0"),record(input = "1"),record(input = " ")| parse input, "CDOUBLE:result"
Specify configuration parameters in parentheses after the matcher name: CDOUBLE(min=value, max=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| The minimum of parsed value. If the value is less than this the parsing fails and the output is set to |
|
| The maximum of parsed value. If the value is greater than this the parsing fails and the output is set to |
The data type of the extracted value is double.
The following pattern checks if a comma-decimal value is between 0 and 2:
CDOUBLE(min=0, max=2)
| Description | input (string) | result (boolean) |
|---|---|---|
In range |
|
|
At maximum |
|
|
Above maximum |
|
|
data record(input = "1,5"),record(input = "2,0"),record(input = "2,5")| fieldsAdd result = matchesPattern(input, "CDOUBLE(min=0, max=2)")
Matches integral numbers in the form of [+|-]?[0-9]+ with values in the range -2147483648 to 2147483647. INTEGER is an alias for INT.
INT reads the leading run of digits and stops at the first non-digit character—for example, 2.5 yields 2. However, if that entire digit run forms a value outside the INT range, the result is null; it is not truncated to a shorter in-range prefix. For larger values, use LONG.
Use the following pattern to parse integer values:
INT:result
For example, parsing integer values including negative numbers:
| Description | input (string) | result (long) |
|---|---|---|
Negative |
|
|
Decimal |
|
|
Comma-separated |
|
|
Hexadecimal |
|
|
INT maximum |
|
|
INT maximum + 1 |
|
|
LONG maximum |
|
|
LONG maximum + 1 |
|
|
Whitespace |
|
|
data record(input = "-10"),record(input = "2.5"),record(input = "3,6"),record(input = "0xa01F"),record(input = "2147483647"),record(input = "2147483648"),record(input = "9223372036854775807"),record(input = "9223372036854775808"),record(input = " ")| parse input, "INT:result"
Specify configuration parameters in parentheses after the matcher name: INT(min=value, max=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| The minimum of parsed value. If the value is less than this the parsing fails and the output is set to |
|
| The maximum of parsed value. If the value is greater than this the parsing fails and the output is set to |
The data type of the extracted value is long.
The following pattern checks if an integer value is a valid HTTP 2xx status code:
INT(min=200, max=299)
| Description | input (string) | result (boolean) |
|---|---|---|
Success—in range |
|
|
Success—in range |
|
|
Client error—out of range |
|
|
Server error—out of range |
|
|
data record(input = "200"),record(input = "201"),record(input = "404"),record(input = "500")| fieldsAdd result = matchesPattern(input, "INT(min=200, max=299)")
Given the following input:
GET /api/users HTTP/1.1 200 1234
Use the following pattern to extract the HTTP status code and response size:
LD 'HTTP/1.1 ' INT:status SPACE INT:bytes
status (long) | bytes (long) |
|---|---|
|
|
data record(input = "GET /api/users HTTP/1.1 200 1234")| parse input, "LD 'HTTP/1.1 ' INT:status SPACE INT:bytes"
Matches integral numbers in hexadecimal notation [+|-]?0?x?[0-9a-fA-F]+ with values in the range -2147483648 to 2147483647.
HEXINT reads the leading run of hexadecimal digits and stops at the first character that is not a hex digit—for example, 10fEgh yields 4350. However, if that entire run forms a value outside the HEXINT range, the result is null; it is not truncated to a shorter in-range prefix. For larger values, use HEXLONG.
Use the following pattern to parse hexadecimal integer values:
HEXINT:result
For example, parsing hexadecimal values in different notations:
| Description | input (string) | result (long) |
|---|---|---|
Prefixed with |
|
|
Prefixed with |
|
|
Prefixed with |
|
|
Plain hex digits |
|
|
Above INT range |
|
|
LONG maximum |
|
|
LONG maximum + 1 |
|
|
Non-hex text |
|
|
Whitespace |
|
|
data record(input = "0xa01F"),record(input = "x3"),record(input = "-xFE"),record(input = "10fE"),record(input = "0xFFFFFFFF"),record(input = "0x7FFFFFFFFFFFFFFF"),record(input = "0x8000000000000000"),record(input = "word"),record(input = " ")| parse input, "HEXINT:result"
Specify configuration parameters in parentheses after the matcher name: HEXINT(min=value, max=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| The minimum of parsed value. If the value is less than this the parsing fails and the output is set to |
|
| The maximum of parsed value. If the value is greater than this the parsing fails and the output is set to |
The data type of the extracted value is long.
The following pattern checks if a hex value is within the 16-bit unsigned range:
HEXINT(min=0, max=65535)
| Description | input (string) | result (boolean) |
|---|---|---|
In range |
|
|
In range |
|
|
Negative—below minimum |
|
|
data record(input = "0xa01F"),record(input = "10fE"),record(input = "-xFE")| fieldsAdd result = matchesPattern(input, "HEXINT(min=0, max=65535)")
Given the following input:
SIGSEGV at address 0x7ffd3a2c
Use the following pattern to extract the memory address:
'SIGSEGV at address ' HEXINT:address
address (long) |
|---|
|
data record(input = "SIGSEGV at address 0x7ffd3a2c")| parse input, "'SIGSEGV at address ' HEXINT:address"
Matches integral numbers in the form of [+|-]?[0-9]+ with values in the range -9223372036854775808 to 9223372036854775807.
LONG reads the leading run of digits and stops at the first non-digit character—for example, 2.5 yields 2. However, if that entire digit run forms a value outside the LONG range, the result is null; it is not truncated to a shorter in-range prefix.
Use the following pattern to parse long integer values:
LONG:result
For example, parsing long values including large numbers:
| Description | input (string) | result (long) |
|---|---|---|
Negative |
|
|
Decimal |
|
|
Comma-separated |
|
|
Hexadecimal |
|
|
INT maximum |
|
|
INT maximum + 1 |
|
|
LONG maximum |
|
|
LONG maximum + 1 |
|
|
Whitespace |
|
|
data record(input = "-10"),record(input = "2.5"),record(input = "3,6"),record(input = "0xa01F"),record(input = "2147483647"),record(input = "2147483648"),record(input = "9223372036854775807"),record(input = "9223372036854775808"),record(input = " ")| parse input, "LONG:result"
Specify configuration parameters in parentheses after the matcher name: LONG(min=value, max=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| The minimum of parsed value. If the value is less than this the parsing fails and the output is set to |
|
| The maximum of parsed value. If the value is greater than this the parsing fails and the output is set to |
The data type of the extracted value is long.
The following pattern checks if a long value is non-negative:
LONG(min=0)
| Description | input (string) | result (boolean) |
|---|---|---|
LONG maximum |
|
|
Negative—below minimum |
|
|
data record(input = "9223372036854775807"),record(input = "-2000")| fieldsAdd result = matchesPattern(input, "LONG(min=0)")
Given the following input:
event id=1576590440679 type=login
Use the following pattern to extract the event identifier:
'event id=' LONG:id SPACE LD
id (long) |
|---|
|
data record(input = "event id=1576590440679 type=login")| parse input, "'event id=' LONG:id SPACE LD"
Matches integral numbers in hexadecimal notation [+|-]?0?x?[0-9a-fA-F]+ with values in the range -9223372036854775808 to 9223372036854775807.
HEXLONG reads the leading run of hexadecimal digits and stops at the first character that is not a hex digit—for example, 10fEgh yields 4350. However, if that entire run forms a value outside the HEXLONG range, the result is null; it is not truncated to a shorter in-range prefix.
Use the following pattern to parse hexadecimal long values:
HEXLONG:result
For example, parsing hexadecimal long values in different notations:
| Description | input (string) | result (long) |
|---|---|---|
Prefixed with |
|
|
Prefixed with |
|
|
Prefixed with |
|
|
Plain hex digits |
|
|
Above INT range |
|
|
LONG maximum |
|
|
LONG maximum + 1 |
|
|
Non-hex text |
|
|
Whitespace |
|
|
data record(input = "0xa01F"),record(input = "x3"),record(input = "-xFE"),record(input = "10fE"),record(input = "0xFFFFFFFF"),record(input = "0x7FFFFFFFFFFFFFFF"),record(input = "0x8000000000000000"),record(input = "word"),record(input = " ")| parse input, "HEXLONG:result"
Specify configuration parameters in parentheses after the matcher name: HEXLONG(min=value, max=value):result.
| Parameter | Type | Description |
|---|---|---|
|
| The minimum of parsed value. If the value is less than this the parsing fails and the output is set to |
|
| The maximum of parsed value. If the value is greater than this the parsing fails and the output is set to |
The data type of the extracted value is long.
The following pattern checks if a hex long value is non-negative:
HEXLONG(min=0)
| Description | input (string) | result (boolean) |
|---|---|---|
Large positive value |
|
|
Small positive value |
|
|
data record(input = "0xFFFFFFFFFFFFFF"),record(input = "10fE")| fieldsAdd result = matchesPattern(input, "HEXLONG(min=0)")