log_template_matches
Returns true when a value has the same structural log template as a sample line: `log_template_hash(tostring(field)) == log_template_hash(sample)`.
Use it to select every row of a pattern found with log_template_hash or extract_log_template, whatever its variable values (numbers, IDs, IPs, quoted strings). The sample must be a constant string. The comparison is exact up to 64-bit hash collisions. A null or empty field matches an empty sample, as tostring turns null into an empty string. The sample's literal words are also required as has_cs terms, so the query skips chunks whose bloom filter shows they lack them.
Syntax
log_template_matches(field, sample)Parameters
Prop
Type
Given a dynamic field
This parameter is string-only. In permissive mode — the default — almost every field arrives as a dynamic, so passing one works because Berserk injects asstring: extract-or-null, the value when it really is a string and null otherwise, so the call yields null (a predicate yields false). A property bag or array is therefore not matched, and tostring() is never applied implicitly — use it explicitly to match a bag's JSON text, keys included. Strict mode rejects the dynamic instead of coercing it. See String coercion and the asXXX family.
Returns: bool
Examples
Example 1 — Rows with the same template as a sample line
datatable(body:string)[
"GET /api/v1/raids/793 took 12ms",
"GET /api/v1/raids/845 took 7ms",
"POST /longships"
]
| where log_template_matches(body, "GET /api/v1/raids/1 took 1ms")| body (string) |
|---|
| GET /api/v1/raids/793 took 12ms |
| GET /api/v1/raids/845 took 7ms |