log_template_regex
Generates a regex pattern that matches log lines with the same structural template.
Variable tokens (numbers, UUIDs, IPs, hex, quoted strings) are replaced with regex wildcards while literal text is preserved. The output is designed for use with matches regex to leverage bloom filter optimization.
Syntax
log_template_regex(source)See Regex Syntax for the full regular expression reference.
Parameters
Prop
Type
Given a dynamic field
This parameter is string-only. In permissive mode — the default — almost every field arrives as a dynamic, so passing one works because Berserk injects asstring: extract-or-null, the value when it really is a string and null otherwise, so the call yields null (a predicate yields false). A property bag or array is therefore not matched, and tostring() is never applied implicitly — use it explicitly to match a bag's JSON text, keys included. Strict mode rejects the dynamic instead of coercing it. See String coercion and the asXXX family.
Returns: string
Examples
Example 1
print log_template_regex("raid on monastery 793 from 10.0.0.1")| print_0 (string) |
|---|
| ^raid on monastery \d+(?:.\d+)?(?:[eE][+-]?\d+)? from \d{1,3}.\d{1,3}.\d{1,3}.\d{1,3}$ |