This topic explains how to use SPL to replicate the functionality of processing plugins.
Background information
SPL vs. native plugins
Regex parsing
Sample log:
127.0.0.1 - - [07/Jul/2022:10:43:30 +0800] "POST /PutData?Category=YunOsAccountOpLog" 0.024 18204 200 37 "-" "aliyun-sdk-java"Regex parsing | SPL |
The Data Parsing (Regex Mode) plugin uses the regular expression | The SPL statement is: |
Output preview
{
"ip": "127.0.0.1",
"time": "07/Jul/2022:10:43:30",
"method": "POST",
"url": "/PutData?Category=YunOsAccountOpLog",
"request_time": "0.024",
"request_length": "18204",
"status": "200",
"length": "37",
"ref_url": "-",
"browser": "aliyun-sdk-java",
"__time__": "1713184059"
}Delimiter parsing
Sample log:
127.0.0.1,07/Jul/2022:10:43:30 +0800,POST,PutData Category=YunOsAccountOpLog,0.024,18204,200,37,-,aliyun-sdk-javaDelimiter parsing | SPL |
The Data Parsing (Delimiter Mode) plugin parses the log by using a comma (,) as the delimiter. For more information, see Collect text logs from servers. | The SPL statement is: |
Output preview
{
"ip": "127.0.0.1",
"time": "07/Jul/2022:10:43:30 +0800",
"method": "POST",
"url": "PutData?Category=YunOsAccountOpLog",
"request_time": "0.024",
"request_length": "18204",
"status": "200",
"length": "37",
"ref_url": "-",
"browser": "aliyun-sdk-java",
"__time__": "1713231487"
}JSON parsing
Sample log:
{"url": "POST /PutData?Category=YunOsAccountOpLog HTTP/1.1","ip": "10.200.98.220", "user-agent": "aliyun-sdk-java","request": "{\"status\":\"200\",\"latency\":\"18204\"}","time": "07/Jul/2022:10:30:28"}JSON parsing | SPL |
For more information, see Collect text logs in JSON mode. Select Data Parsing (JSON Mode) plugin for the processing plugin type, and set the original field to content. | The SPL statement is: |
Output preview
{
"url": "POST /PutData?Category=YunOsAccountOpLog HTTP/1.1",
"ip": "10.200.98.220",
"user-agent": "aliyun-sdk-java",
"request": "{\"status\":\"200\",\"latency\":\"18204\"}",
"time": "07/Jul/2022:10:30:28"
}Regex and time parsing
Sample log:
127.0.0.1 - - [2024-11-05T15:47:05 +0800] "POST /PutData?Category=YunOsAccountOpLog" 0.024 18204 200 37 "-" "aliyun-sdk-java"Regex and time parsing | SPL |
| The SPL statement is: |
Regex parsing and data filtering
Sample log:
127.0.0.1 - - [2024-11-05T15:47:05 +0800] "POST /PutData?Category=YunOsAccountOpLog" 0.024 18204 200 37 "-" "aliyun-sdk-java"Regex parsing and data filtering | SPL |
| The SPL statement is: |
Output preview
{
"ip": "127.0.0.1",
"time": "2024-11-05T15:47:05",
"method": "POST",
"url": "/PutData?Category=YunOsAccountOpLog",
"request_time": "0.024",
"request_length": "18204",
"status": "200",
"length": "37",
"ref_url": "-",
"browser": "aliyun-sdk-java",
"__time__": "1713238839"
}Data masking
Sample log:
{"account":"1812213231432969","password":"04a23f38"}Data masking | SPL |
Use the Data masking and encryption plugins to mask the The original field is content, the desensitization method is const, the replacement string is | The SPL statement is: |
Output preview
{
"content": "{"account":"1812213231432969","password":"******"}"
}SPL vs. extended plugins
Add field
Sample log:
this is a test logAdd field | SPL |
By default, the log is stored in the | The SPL statement is: |
Output preview
{
"content": "this is a test log",
"service": "A"
}JSON parsing and drop field
Sample log:
{"key1": 123456, "key2": "abcd"}JSON parsing and drop field | SPL |
| The SPL statement is: |
Output preview
{
"key2": "abcd"
}JSON parsing and rename fields
Sample log:
{"key1": 123456, "key2": "abcd"}JSON parsing and rename fields | SPL |
| The SPL statement is: |
Output preview
{
"new_key1": "123456",
"key2": "abcd"
}JSON parsing and log filtering
Sample log:
{"ip": "10.**.**.**", "method": "POST", "browser": "aliyun-sdk-java"}
{"ip": "10.**.**.**", "method": "POST", "browser": "chrome"}
{"ip": "192.168.**.**", "method": "POST", "browser": "aliyun-sls-ilogtail"}JSON parsing and log filtering | SPL |
| The SPL statement is: |
Output preview
{
"ip": "10.**.**.**",
"method": "POST",
"browser": "chrome"
}JSON parsing and field value mapping
Sample log:
{"_ip_":"192.168.*.*","Index":"900000003"}
{"_ip_":"255.255.**.**","Index":"3"}JSON parsing and field value mapping | SPL |
| The SPL statement is: |
Output preview
{
"_ip_": "192.168.*.*",
"Index": "900000003",
"_processed_ip_": "default login"
}String replacement
Sample log:
hello,how old are you? nice to meet youString replacement | SPL |
Use the Field processing plugins to replace "how old are you?" with an empty value. | The SPL statement is: |
Output preview
{
"content": "hello, nice to meet you"
}Data encoding
Sample log:
this is a test logBASE64 encoding
BASE64 encoding | SPL |
For more information, see Data masking and encryption plugins. For Processing Plugin Type, select BASE64 (encode), set Original Field to content, and set Result Field to content1. | The SPL statement is: |
Output preview
{
"content": "this is a test log",
"content1": "dGhpcyBpcyBhIHRlc3QgbG9n"
}MD5 encoding
MD5 | SPL |
For more information, see Data masking and encryption plugins. The processing plugin type is MD5, the original field is content, and the result field is test. | The SPL statement is: |
Output preview
{
"content": "this is a test log",
"test": "e7d7063444dd5593855de31741584288"
}Additional SPL capabilities
Mathematical calculations
Sample log
4SPL statement
The cast function converts data types. For more information about the
power,round, andsqrtfunctions, see Mathematical functions.* | extend val = cast(content as double) | extend power_test = power(val, 2) | extend round_test = round(val) | extend sqrt_test = sqrt(val)Output preview
{ "content": "4", "power_test": 16.0, "round_test": 4.0, "sqrt_test": 2.0, "val": 4.0 }
URL operations
URL encoding and decoding
Sample log
https://home.console.alibabacloud.com/home/dashboard/ProductAndServiceSPL statement
For more information about the
url_encodeandurl_decodefunctions, see URL functions.* | extend encoded = url_encode(content) | extend decoded = url_decode(encoded)Output preview
{ "content": "https://home.console.alibabacloud.com/home/dashboard/ProductAndService", "decoded": "https://home.console.alibabacloud.com/home/dashboard/ProductAndService", "encoded": "https%3A%2F%2Fhome.console.alibabacloud.com%2Fhome%2Fdashboard%2FProductAndService" }
URL extraction
Sample log
https://sls.console.alibabacloud.com:443/lognext/project/dashboard-all/logsearch/nginx-demo?accounttraceid=d6241a173f88471c91d3405cda010ff5ghdwSPL statement
For more information about the functions used in this SPL statement, see URL functions.
* | extend host = url_extract_host(content) | extend query = url_extract_query(content) | extend path = url_extract_path(content) | extend protocol = url_extract_protocol(content) | extend port = url_extract_port(content) | extend param = url_extract_parameter(content, 'accounttraceid')Output preview
{ "content": "https://sls.console.alibabacloud.com:443/lognext/project/dashboard-all/logsearch/nginx-demo?accounttraceid=d6241a173f88471c91d3405cda010ff5ghdw", "host": "sls.console.alibabacloud.com", "param": "d6241a173f88471c91d3405cda010ff5ghdw", "path": "/lognext/project/dashboard-all/logsearch/nginx-demo", "port": "443", "protocol": "https", "query": "accounttraceid=d6241a173f88471c91d3405cda010ff5ghdw" }
Comparison and logical operators
Sample log
{"num1": 199, "num2": 10, "num3": 9}SPL statement
The cast function converts data types, and SPL instructions and functions extract fields.
* | parse-json content | extend compare_result = cast(num1 as double) > cast(num2 as double) AND cast(num2 as double) > cast(num3 as double)Output preview
{ "compare_result": "true", "content": "{\"num1\": 199, \"num2\": 10, \"num3\": 9}", "num1": "199", "num2": "10", "num3": "9" }