Berserk Docs
Scalar FunctionsLogging Functions

log_template_matches

Returns true when a value has the same structural log template as a sample line: `log_template_hash(tostring(field)) == log_template_hash(sample)`.

Use it to select every row of a pattern found with log_template_hash or extract_log_template, whatever its variable values (numbers, IDs, IPs, quoted strings). The sample must be a constant string. The comparison is exact up to 64-bit hash collisions. A null or empty field matches an empty sample, as tostring turns null into an empty string. The sample's literal words are also required as has_cs terms, so the query skips chunks whose bloom filter shows they lack them.

Syntax

log_template_matches(field, sample)

Parameters

Prop

Type

Given a dynamic field

This parameter is string-only. In permissive mode — the default — almost every field arrives as a dynamic, so passing one works because Berserk injects asstring: extract-or-null, the value when it really is a string and null otherwise, so the call yields null (a predicate yields false). A property bag or array is therefore not matched, and tostring() is never applied implicitly — use it explicitly to match a bag's JSON text, keys included. Strict mode rejects the dynamic instead of coercing it. See String coercion and the asXXX family.

Returns: bool

Examples

Example 1 — Rows with the same template as a sample line

datatable(body:string)[
  "GET /api/v1/raids/793 took 12ms",
  "GET /api/v1/raids/845 took 7ms",
  "POST /longships"
]
| where log_template_matches(body, "GET /api/v1/raids/1 took 1ms")
body (string)
GET /api/v1/raids/793 took 12ms
GET /api/v1/raids/845 took 7ms

On this page