This topic explains the syntax of field value extraction functions, including their parameters and examples.
Function list
Type | Function | Description |
Regular expression extraction | Extracts a value from a field using a regular expression and assigns it to another field. This function can be combined with other functions. For a related example, see Parse Java error logs. | |
JSON extraction | Processes a JSON object in a specified field. Operations include expanding the object, extracting data with JMESPath, or extracting and expanding. This function can be combined with other functions. For a related example, see Transform complex JSON data. | |
Delimiter-based extraction | Extracts values for multiple fields from a source field using a delimiter and predefined field names.
These functions can be combined with other functions. For a related example, see Parse CSV-formatted logs. | |
Key-value extraction | Extracts key-value pairs from one or more source fields using a specified quote character. This function can be combined with other functions. For a related example, see Extract dynamic key-value pairs from a string. | |
Extracts key-value pairs from a source field using a delimiter. | ||
Syslog standard extraction | Calculates facility and severity from a priority value based on the Syslog protocol and maps them to the corresponding level. This function can be combined with other functions. For a related example, see Parse standard Syslog format data. | |
Rule-based extraction | Extracts strings using the rules defined in anchor_rules. |
e_regex
Extracts values from a field based on a regular expression and assigns them to other fields.
Syntax
e_regex(key, regex, fields_info, mode="fill-auto", pack_json=None)Parameters
Parameter
Type
Required
Description
key
Any
Yes
The source field. If the field does not exist, the function does nothing. For information about how to configure special field names, see event types.
regex
String
Yes
The regular expression used to extract field values. It supports both capturing and non-capturing groups.
NoteA non-capturing group, which requires the
?:prefix, is sometimes used for grouping. For example,\w+@\w+\.\w(?:\.\cn)?. For more information, see non-capturing groups.fields_info
String/List/Dict
No
The target fields for the matched values. This parameter is required if you do not use named capturing groups in the regular expression.
mode
String
No
The overwrite mode for the fields. The default value is fill-auto. For more information about the values and their meanings, see field extraction check and overwrite mode.
pack_json
String
No
Packs all matched results from the regular expression into the field specified by
pack_json. The default value isNone, which indicates that packing is disabled.Response
Returns the log, updated with the extracted fields and their values.
Examples
Example 1: Extract a single value
raw log
msg: 192.168.0.1 http://... 127.0.0.0transformation rule
# Extract the first IP address from the msg field. e_regex("msg",r"\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}","ip")transformation result
msg: 192.168.0.1 http://... 127.0.0.0 ip: 192.168.0.1
Example 2: Extract multiple values
raw log
msg: 192.168.0.1 http://... 127.0.0.0transformation rule
# Extract two IP addresses from the msg field and assign them to server_ip and client_ip. e_regex("msg",r"\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}",["server_ip","client_ip"])transformation result
msg: 192.168.0.1 http://... 127.0.0.0 server_ip: 192.168.0.1 client_ip: 127.0.0.0
Example 3: Extract values by using a capturing group.
raw log
content: start sys version: deficience, err: 2transformation rule
# Use a regular expression to capture the version and error values from the content field. e_regex("content",r"start sys version: (\w+),\s*err: (\d+)",["version","error"])transformation result
content: start sys version: deficience, err: 2 error: 2 version: deficience
Example 4: Extract values by using a named capturing group
raw log
content: start sys version: deficience, err: 2transformation rule
e_regex("content",r"start sys version: (?P<version>\w+),\s*err: (?P<error>\d+)")transformation result
content: start sys version: deficience, err: 2 error: 2 version: deficience
Example 5: Dynamically create a field name and value from the dict field.
raw log
dict: verify:123transformation rule
e_regex("dict",r"(\w+):(\d+)",{r"k_\1": r"v_\2"})transformation result
dict: verify:123 k_verify: v_123
Example 6: Extract and pack a value into the name field.
raw log
msg: 192.168.0.1 http://... 127.0.0.0transformation rule
e_regex("msg", r"\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}", "ip", pack_json="name")transformation result
msg:192.168.0.1 http://... 127.0.0.0 name:{"ip": "192.168.0.1"}
Example 7: Dynamically create fields from the dict field and pack them into the name field.
raw log
dict: x:123, y:456, z:789transformation rule
e_regex("dict", r"(\w+):(\d+)", {r"k_\1": r"v_\2"}, pack_json="name")transformation result
dict:x:123, y:456, z:789 name:{"k_x": "v_123", "k_y": "v_456", "k_z": "v_789"}
Example 8: Extract and pack values from a capturing group into the name field.
raw log
content: start sys version: deficience, err: 2transformation rule
e_regex( "content", r"start sys version: (\w+),\s*err: (\d+)", ["version", "error"],pack_json="name")transformation result
content:start sys version: deficience, err: 2 name:{"version": "deficience", "error": "2"}
References
You can combine this function with other functions. For a related example, see Parse Java error logs.
e_json
Performs JSON operations on a JSON object in a specified field. These operations include expanding the JSON data, extracting data with a JMESPath expression, or extracting and then expanding a JSON subset.
Syntax
e_json(key, expand=None, depth=100, prefix="__", suffix="__", fmt="simple", sep=".", expand_array=True, fmt_array="{parent}_{index}", include_node=r"[\u4e00-\u9fa5\u0800-\u4e00a-zA-Z][\w\-\.]*", exclude_node="", include_path="", exclude_path="", jmes="", output="", jmes_ignore_none=False, mode='fill-auto' )NoteIf the target string is not a valid JSON object, the
e_jsonfunction returns the original string without parsing it.Parameters
Parameter
Type
Required
Description
key
String
Yes
The name of the input field. If the field does not exist, the function does nothing. For information about how to configure special field names, see Event types.
expand
Boolean
No
Specifies whether to expand the field.
If the jmes parameter is not configured, the default value is True, which expands the field.
If the jmes parameter is configured, the default value is False, which does not expand the field.
depth
Number
No
The depth to which the function expands the field. Valid values: 1 to 2000. The default value is 100. A value of 1 expands only the first level.
prefix
String
No
The prefix to add to each expanded field name.
suffix
String
No
The suffix to add to each expanded field name.
fmt
String
No
The formatting method for expanded field names. Valid values:
simple (default): Uses the current node name as the field name. The format is
{prefix}{current}{suffix}.full: Combines the full path from the source field to the current node as the field name. The format is
{parent_list_str}{sep}{prefix}{current}{suffix}. The delimiter is specified by thesepparameter. The default delimiter is..parent: Combines the current node name with its immediate parent node name. The format is
{parent}{sep}{prefix}{current}{suffix}. The delimiter is specified by thesepparameter. The default delimiter is..root: Combines the current node name with the root node name. The format is
{parent_list[0]}{sep}{prefix}{current}{suffix}. The delimiter is specified by thesepparameter. The default delimiter is..
sep
String
No
The delimiter between parent and child node names. This parameter applies when
fmtis set to full, parent, or root. The default value is..expand_array
Boolean
No
Specifies whether to expand arrays. The default value is
True.fmt_array
String
No
The formatting method for array expansion. The format is
{parent_rlist[0]}_{index}. You can also build a custom format string by using up to five placeholders:parent_list,current,sep,prefix, andsuffix.include_node
String/Number
No
The node allowlist specifies the node names to include for filtering. By default, only nodes whose names consist of Chinese characters, digits, letters, and
_.-are automatically expanded.exclude_node
String
No
A regular expression that defines a blacklist of node names to exclude.
include_path
String
No
A regular expression that defines a whitelist of node paths to include.
exclude_path
String
No
A regular expression that defines a blacklist of node paths to exclude.
jmes
String
No
A JMESPath expression to extract data from the JSON object.
output
String
No
The name of the output field for the value extracted using the JMESPath expression.
jmes_ignore_none
Boolean
No
Specifies the behavior when the JMESPath expression finds no value. If True (the default), the extraction is ignored. If
False, an empty string is returned.mode
String
No
The field overwrite mode. The default value is fill-auto. For more information, see Field extraction check and overwrite modes.
JSON expansion filtering
If a node whitelist is set, only nodes in the whitelist are included in the result. Example regular expression for a node whitelist:
e_json("json_data_filed", ...., include_node=r'key\d+').If a node blacklist is set, nodes in the blacklist are excluded from the result. Example regular expression for a node blacklist:
e_json("json_data_filed", ...., exclude_node=r'key\d+').For node path expansion, the
include_pathandexclude_pathregular expressions are matched against the start of the path. Node paths use.as the delimiter.
JMESPath filtering
Use JMESPath to select and compute data.
Select a list of element attributes from a specific JSON path:
e_json(..., jmes="cve.vendors[*].product",output="product")Concatenate element attributes from a specific JSON path with a comma (,):
e_json(..., jmes="join(',', cve.vendors[*].name)",output="vendors")Calculate the maximum attribute value for elements in a specific JSON path:
e_json(..., jmes="max(words[*].score)",output="hot_word")Return an empty string if a specific path does not exist or is empty:
e_json(..., jmes="max(words[*].score)",output="hot_word", jmes_ignore_none=False)
parent_list and parent_rlist
The following examples demonstrate their usage.
Raw log:
data: { "k1": 100,"k2": {"k3": 200,"k4": {"k5": 300}}}parent_listarranges parent nodes from left to right.e_json("data", fmt='{parent_list[0]}-{parent_list[1]}#{current}')Transformation result:
data:{ "k1": 100,"k2": {"k3": 200,"k4": {"k5": 300}}} data-k2#k3:200 data-k2#k5:300parent_rlistarranges parent nodes from right to left.e_json("data", fmt='{parent_rlist[0]}-{parent_rlist[1]}#{current}')Transformation result:
data:{ "k1": 100,"k2": {"k3": 200,"k4": {"k5": 300}}} k2-data#k3:200 k4-k2#k5:300
Response
Returns the log with the newly added fields.
Examples
Example 1: Expanding a field.
Raw log
data: {"k1": 100, "k2": 200}Transformation rule
e_json("data",depth=1)Transformation result
data: {"k1": 100, "k2": 200} k1: 100 k2: 200
Example 2: Adding a prefix and a suffix to field names.
Raw log
data: {"k1": 100, "k2": 200}Transformation rule
e_json("data", prefix="data_", suffix="_end")Transformation result
data: {"k1": 100, "k2": 200} data_k1_end: 100 data_k2_end: 200
Example 3: Expanding a field using different formats.
Raw log
data: {"k1": 100, "k2": {"k3": 200, "k4": {"k5": 300} } }fmt=full
e_json("data", fmt='full')data: {"k1": 100, "k2": {"k3": 200, "k4": {"k5": 300} } } data.k1: 100 data.k2.k3: 200 data.k2.k4.k5: 300fmt=parent
e_json("data", fmt='parent')data: {"k1": 100, "k2": {"k3": 200, "k4": {"k5": 300} } } data.k1: 100 k2.k3: 200 k4.k5: 300fmt=root
e_json("data", fmt='root')data: {"k1": 100, "k2": {"k3": 200, "k4": {"k5": 300} } } data.k1: 100 data.k3: 200 data.k5: 300
Example 4: Extracting JSON data with a specified delimiter, prefix, and suffix.
Raw log
data: {"k1": 100, "k2": {"k3": 200, "k4": {"k5": 300} } }Transformation rule
e_json("data", fmt='parent', sep="@", prefix="__", suffix="__")Transformation result
data: {"k1": 100, "k2": {"k3": 200, "k4": {"k5": 300} } } data@__k1__:100 k2@__k3__:200 k4@__k5__:300
Example 5: Using the fmt_array parameter to extract JSON data as an array.
Raw log
people: [{"name": "xm", "sex": "boy"}, {"name": "xz", "sex": "boy"}, {"name": "xt", "sex": "girl"}]Transformation rule
e_json("people", fmt='parent', fmt_array="{parent_rlist[0]}-{index}")Transformation result
people: [{"name": "xm", "sex": "boy"}, {"name": "xz", "sex": "boy"}, {"name": "xt", "sex": "girl"}] people-0.name: xm people-0.sex: boy people-1.name: xz people-1.sex: boy people-2.name: xt people-2.sex: girl
Example 6: Using a JMESPath expression to extract a JSON object.
Raw log
data: { "people": [{"first": "James", "last": "d"},{"first": "Jacob", "last": "e"}],"foo": {"bar": "baz"}}Transformation rule
e_json("data", jmes='foo', output='jmes_output0') e_json("data", jmes='foo.bar', output='jmes_output1') e_json("data", jmes='people[0].last', output='jmes_output2') e_json("data", jmes='people[*].first', output='jmes_output3')Transformation result
data: { "people": [{"first": "James", "last": "d"},{"first": "Jacob", "last": "e"}],"foo": {"bar": "baz"}} jmes_output0: {"bar": "baz"} jmes_output1: baz jmes_output2: d jmes_output3: ["James", "Jacob"]
Further reading
For an example of combining this function with others, see Complex JSON data transformation.
e_csv, e_psv, and e_tsv
These functions extract multiple fields from a specified field using a custom delimiter and predefined field names.
e_csv: The default delimiter is a comma (,).
e_psv: The default delimiter is a vertical bar (|).
e_tsv: The default delimiter is a tab character (
\t).
Syntax
e_csv(input field name, output field list, sep=",", quote='"', restrict=True, mode="fill-auto") e_psv(input field name, output field list, sep="|", quote='"', restrict=True, mode="fill-auto") e_tsv(input field name, output field list, sep="\t", quote='"', restrict=True, mode="fill-auto")Parameters
Parameter
Type
Required
Description
input field name
Any
Yes
The name of the input field. If the specified field does not exist, the function takes no action. For information about how to specify special field names, see Event types.
output field list
Any
Yes
The names of the output fields that store the parsed values.
You can provide the names as a list of strings, such as
["error", "message", "result"].If the field names do not contain commas, you can also provide a single string with names separated by commas, such as
"error, message, result".For information about how to specify special field names, see Event types.
sep
String
No
The delimiter. It must be a single character.
quote
String
No
The character used to enclose values. Use this when a value contains the delimiter.
restrict
Boolean
No
Specifies whether to use restricted mode. The default value is True, which enables restricted mode. This parameter determines the behavior when the number of parsed values does not match the number of output fields:
In restricted mode (True), the function takes no action.
In non-restricted mode (False), the function assigns values to the matching fields.
mode
String
No
The field overwrite mode. The default value is fill-auto. For more information about the values and their meanings, see Field extraction check and overwrite modes.
Response
Returns the log with the new fields added.
Examples
The following example uses
e_csv. Thee_psvande_tsvfunctions operate similarly.Raw log
content: 192.168.0.100,10/Jun/2019:11:32:16 +0800,example.aliyundoc.com,GET /zf/11874.html HTTP/1.1,200,0.077,6404,192.168.0.100:8001,200,0.060,https://image.developer.aliyundoc.com/s?q=how-to-make-noodles&from=wy878378&uc_param_str=dnntnwvepffrgibijbprsvdsei,-,Mozilla/5.0 (Linux; Android 9; HWI-AL00 Build/HUAWEIHWI-AL00) AppleWebKit/537.36,-,-Transformation rule
e_csv("content", "remote_addr, time_local,host,request,status,request_time,body_bytes_sent,upstream_addr,upstream_status, upstream_response_time,http_referer,http_x_forwarded_for,http_user_agent,session_id,guid")Result
content: 192.168.0.100,10/Jun/2019:11:32:16 +0800,example.aliyundoc.com,GET /zf/11874.html HTTP/1.1,200,0.077,6404,192.168.0.100:8001,200,0.060,https://image.developer.aliyundoc.com/s?q=how-to-make-noodles&from=wy878378&uc_param_str=dnntnwvepffrgibijbprsvdsei,-,Mozilla/5.0 (Linux; Android 9; HWI-AL00 Build/HUAWEIHWI-AL00) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Mobile Safari/537.36,-,- body_bytes_sent: 6404 guid: - host: example.aliyundoc.com http_referer: https://image.developer.aliyundoc.com/s?q=how-to-make-noodles&from=wy878378&uc_param_str=dnntnwvepffrgibijbprsvdsei http_user_agent: Mozilla/5.0 (Linux; Android 9; HWI-AL00 Build/HUAWEIHWI-AL00) AppleWebKit/537.36 http_x_forwarded_for: - remote_addr: 192.168.0.100 request: GET /zf/11874.html HTTP/1.1 request_time: 0.077 session_id: - status: 200 time_local: 10/Jun/2019:11:32:16 +0800 topic: syslog-forwarder upstream_addr: 192.168.0.100:8001 upstream_response_time: 0.060 upstream_status: 200
More information
These functions can be combined with other functions. For a related example, see Parse CSV-formatted logs.
e_kv
Extracts key-value pairs from one or more input fields.
Syntax
e_kv(field_or_list, sep="=", quote='"', escape=False, prefix="", suffix="", mode="fill-auto")Parameters
Parameter
Type
Required
Description
field_or_list
String or list of strings
Yes
The name of one or more input fields. For information about how to specify special field names, see Event types.
sep
String
No
The key-value separator, which can be a regular expression. The default value is
=.NoteYou can use non-capturing groups, but not capturing groups. For more information, see Grouping.
quote
String
No
The character used to enclose values. The default value is
".NoteThe value of an extracted dynamic key-value pair is typically enclosed in quotation marks, for example,
a="abc"andb="xyz". If a value is not enclosed in quotation marks, the system extracts only a value that consists of the following characters:Chinese characters, letters, numbers, and the symbols _-.%~. For example, froma=ab12_-.%~|abc b=123, the system extractsa: ab12_-.%~andb: 123.escape
Boolean
No
Controls whether to interpret escape characters in values. The default value is
False. For example, from the inputkey="abc\"xyz", by default, the function extracts the valueabc\for thekeyfield. If you setescape=True, the extracted value isabc"xyz.prefix
String
No
The prefix to add to the names of extracted fields.
suffix
String
No
The suffix to add to the names of extracted fields.
mode
String
No
The field overwrite mode. The default value is fill-auto. For more information about available modes, see Field extraction check and overwrite modes.
Response
Adds the extracted key-value pairs to the log as new fields.
Examples
Example 1: Extract key-value pairs using the default delimiter =.
Raw log
http_refer: https://video.developer.aliyundoc.com/s?q=asd&a=1&b=2NoteIf the raw log is
request_uri: a1=1&a2=&a3=3and the value of a2 is empty, the e_kv() function cannot extract a2. You can use the e_regex() function to extract it, for example, e_regex("request_uri",r'(\w+)=([^=&]*)',{r"\1":r"\2"},mode="overwrite").Transformation rule
e_kv("http_refer")Result
http_refer: https://video.developer.aliyundoc.com/s?q=asd&a=1&b=2 q: asd a: 1 b: 2
Example 2: Add a prefix and a suffix to field names.
Raw log
http_refer: https://video.developer.aliyundoc.com/s?q=asd&a=1&b=2Transformation rule
e_kv( "http_refer", sep="=", quote='"', escape=False, prefix="data_", suffix="_end", mode="fill-auto", )Result
http_refer: https://video.developer.aliyundoc.com/s?q=asd&a=1&b=2 data_q_end: asd data_a_end: 1 data_b_end: 2
Example 3: Extract key-value pairs from the
content2field and interpret escape characters using theescapeparameter.Raw log
content2: k1:"v1\"abc", k2:"v2", k3: "v3"Transformation rule
e_kv("content2", sep=":", escape=True)Result
content2: k1:"v1\"abc", k2:"v2", k3: "v3" k1: v1"abc k2: v2 k3: v3
Further reading
For an example of combining this function with others, see Extract dynamic key-value pairs from a string.
e_kv_delimit
Extracts key-value pairs from an input field by using delimiters.
Syntax
e_kv_delimit(field_or_list, pair_sep=r"\s", kv_sep="=", prefix="", suffix="", mode="fill-auto")Parameters
Parameter
Type
Required
Description
field_or_list
string or list of strings
Yes
The name of one or more input fields. For information about how to specify special field names, see event type.
pair_sep
string
No
A regular expression that separates key-value pairs. The default value is
\s. Other examples include\s\wandabc\s.NoteTo use a literal string as a separator, we recommend first replacing it with a single-character delimiter by using the str_replace or regex_replace function. You can then use this function to parse the field.
kv_sep
string
No
A regular expression that separates a key from its value. The default value is
=. The expression is not limited to a single character.NoteYou can use non-capturing groups, but not capturing groups. For more information, see Grouping.
prefix
string
No
The prefix to add to the extracted field names.
suffix
string
No
The suffix to add to the extracted field names.
mode
string
No
The field overwrite mode. The default value is fill-auto. For details about the values, see Field extraction check and overwrite modes.
Response
Returns the log with the extracted key-value pairs added as new fields.
Examples
Example 1: Extracting key-value pairs using the default delimiter
=.Raw log
data: i=c1 k1=v1 k2=v2 k3=v3NoteIf the raw log is
request_uri: a1=1&a2=&a3=3, the e_kv_delimit() function cannot extracta2because its value is empty. To extract pairs with empty values, use the e_regex() function. For example: e_regex("request_uri",r'(\w+)=([^=&]*)',{r"\1":r"\2"}, mode="overwrite").Transformation rule
e_kv_delimit("data")Result
data: i=c1 k1=v1 k2=v2 k3=v3 i: c1 k2: v2 k1: v1 k3: v3
Example 2: Extract key-value pairs by using the delimiter
&?.Raw log
data: k1=v1&k2=v2?k3=v3Transformation rule
e_kv_delimit("data",pair_sep=r"&?")Result
data: k1=v1&k2=v2?k3=v3 k2: v2 k1: v1 k3: v3
Example 3: Extract key-value pairs by using a regular expression as the key-value separator.
Raw log
data: k1=v1 k2:v2 k3=v3Transformation rule
e_kv_delimit("data", kv_sep=r"(?:=|:)")Result
data: k1=v1 k2:v2 k3=v3 k2: v2 k1: v1 k3: v3
e_syslogrfc
Calculates the facility and severity from a priority value according to the syslog protocol and adds the corresponding labels.
Syntax
e_syslogrfc(key, rfc, fields_info=None, mode='overwrite')Parameters
Parameter
Type
Required
Description
key
Any
Yes
The name of the field that contains the
priorityvalue.rfc
String
Yes
The syslog protocol to use. Valid values: SYSLOGRFC3164 and SYSLOGRFC5424.
fields_info
Dict
No
A dictionary that maps default output field names (keys) to custom names (values). The following fields can be renamed:
{"_severity_":"sev","_facility_":"fac","_severitylabel_":"sevlabel","_facilitylabel_":"faclabel"}mode
String
No
The overwrite mode for the output fields. The default value is overwrite. For more information, see Field extraction check and overwrite modes.
Response
Returns the log with the new facility, severity, and label fields.
Examples
Example 1: Extract facility, severity, and label information using the SYSLOGRFC5424 protocol.
raw log
receive_time: 1558663265 _priority_: 13 _version_: 1 _log_time_: 2019-05-06 11:50:16.015554+08:00 _hostname_: iZbp1a65********i2qZ _program_: root _procid_: - _msgid_: - _extradata_: - _content_: twishtransformation rule
e_syslogrfc("_priority_","SYSLOGRFC5424")Result
receive_time: 1558663265 _priority_: 13 _version_: 1 _log_time_: 2019-05-06 11:50:16.015554+08:00 _hostname_: iZbp1a65********i2qZ _program_: root _procid_: - _msgid_: - _extradata_: - _content_: twish _facility_: 1 _severity_: 5 _severitylabel_: Notice: normal but significant condition _facilitylabel_: user-level messages
Example 2: Extract facility, severity, and label information using the SYSLOGRFC5424 protocol and rename the output fields.
raw log
receive_time: 1558663265 _priority_: 13 _version_: 1 _log_time_: 2019-05-06 11:50:16.015554+08:00 _hostname_: iZbp1a65********i2qZ _program_: root _procid_: - _msgid_: - _extradata_: - _content_: twishtransformation rule
e_syslogrfc( "_priority_", "SYSLOGRFC5424", { "_facility_": "fac", "_severity_": "sev", "_facilitylabel_": "_facility_label_", "_severitylabel_": "_severity_label_", }, )Result
receive_time: 1558663265 _priority_: 13 _version_: 1 _log_time_: 2019-05-06 11:50:16.015554+08:00 _hostname_: iZbp1a65********i2qZ _program_: root _procid_: - _msgid_: - _extradata_: - _content_: twish fac: 1 sev: 5 _severity_label_: Notice: normal but significant condition _facility_label_: user-level messages
References
This function can be combined with other functions. For a related example, see Parse standard Syslog format data.
e_anchor
Extracts strings from an input field using rules you define in the anchor_rules parameter.
Syntax
e_anchor(key,anchor_rules,fields,restrict=False,mode="overwrite")Parameters
Parameter
Type
Required
Description
key
Any
Yes
The name of the input field.
anchor_rules
String
Yes
Defines the pattern to extract strings, where an asterisk (*) represents the content to be extracted. For example:
User = *; Severity = *;.The logs displayed on the console are in a Key : Value format with a default space between the colon and the value. When you specify anchor_rules, do not include this space. In the sample log entry, the
contentfield is the target field to be extracted._source_: bin-hangzhou-oss _tag_:_object_: test001/test001-or20190906155735.perf _tag_:_receive_time_: 1582768681 _topic_: content: "Download": 4001792NoteAn asterisk (*) cannot be used as a prefix or suffix in the value of the input field.
fields
Any
Yes
The names of the output fields for the extracted values. You can specify the names as a list of strings, such as
["user", "job", "result"]. If the field names do not contain commas (,), you can also specify them as a single string with names separated by commas, such as"user, job, result". For details on specifying special field names, which can contain special characters but not asterisks (*), see event type.You can skip a field name by using an asterisk (*). For example, if you specify
"user,*,result", only theuserandresultfields are created. For more information, see Example 10.restrict
Boolean
No
Specifies whether to use restricted mode. The default is
False(non-restricted mode). This parameter determines the behavior when the number of extracted values does not match the number of output fields:In restricted mode (
True), the function takes no action.In non-restricted mode (
False), the function assigns values to the corresponding fields in sequence.
mode
String
No
The default value is
overwrite. See field extraction check and overwrite mode for more information.Response
Returns the original log with the extracted fields and their values appended.
Examples
Example 1: Extract multiple values
Raw log
content : "Aug 2 04:06:08: host=192.168.0.10: local/ssl2 notice mcpd[3772]: User=jsmith@example.com: severity=warning: 01070638:5: Pool member 172.31.51.22:0 monitor status down."Transformation rule
e_anchor("content","User=*: severity=*:",["user_field","severity_field"])Result
content : "Aug 2 04:06:08: host=192.168.0.10: local/ssl2 notice mcpd[3772]: User=jsmith@example.com: severity=warning: 01070638:5: Pool member 172.31.51.22:0 monitor status down." user_field : jsmith@example.com severity_field : warning
Example 2: Extract multiple JSON array values
Raw log
content : '"information":{"name_list":["Twiss","Evan","Wind","like"],"university":["UCL","Stanford University","CMU"]},"other":"graduate"'Transformation rule
e_anchor("content",'name_list":*,"university":*},', ["name_list","universities"])Result
content : '"information":{"name_list":["Twiss","Evan","Wind","like"],"university":["UCL","Stanford University","CMU"]},"other":"graduate"' name_list : ["Twiss","Evan","Wind","like"] universities : ["UCL","Stanford University","CMU"]
Example 3: Extract from a log that contains special characters
Raw log
content : (+2019) June 24 "I am iron man"Transformation rule
e_anchor("content", "(+*) * \"*\"",["Year","Date","Msg"])Result
content : (+2019) June 24 "I am iron man" Year : 2019 Date : June 24 Msg : I am iron man
Example 4: Extract from a log that contains an invisible control character (
\x09)Raw log
content : \x09\x09\x09Chrome/55.0 Safari/537.36Transformation rule
e_anchor("content", "\x09\x09\x09*/55.0 */537.36",["Google", "Apple"])Result
content : \x09\x09\x09Chrome/55.0 Safari/537.36 Google : Chrome Apple : Safari
Example 5: Extract the content field, which contains a value with special characters. The field's value is
To...Subject, which followsMESSAGE:.Raw log
content : 12:08:10,651 INFO sample_server ReportEmailer:178 - DEBUG SENDING MESSAGE: To: example@aliyun.com Subject: New line Breaks in MessageTransformation rule
e_anchor("content","* INFO *: \n To: *\n Subject: *",["time","message","email","subject"])Result
content : 12:08:10,651 INFO sample_server ReportEmailer:178 - DEBUG SENDING MESSAGE: To: example@aliyun.com Subject: New line Breaks in Message time : 12:08:10,651 message : sample_server ReportEmailer:178 - DEBUG SENDING MESSAGE email : example@aliyun.com subject : New line Breaks in Message
Example 6: Extract the content field, which contains a value with the invisible special character
\t.Raw log
content : I'm tabbed inTransformation rule
e_anchor("content","\tI'm * in","word") # You can also copy the exact value from the content field to create the pattern. # Do not copy the default space after the colon in the field name. e_anchor("content"," I'm * in","word")Result
content : I'm tabbed in word : tabbed
Example 7: Extract the field content that contains a special character value, which is displayed as
\t.Raw log
content : \tI'm tabbed inTransformation rule
e_anchor("content","\tI'm * in","word") # You can also use the following rule: e_anchor("content"," I'm * in","word")Result
content : \tI'm tabbed in word : tabbed
Example 8: Extract a log in restricted mode
Raw log
content : I used to love having snowball fight with my friends and building snowmen on the streets around our neighborhoodTransformation rule
e_anchor("content","I * to * having",["v_word", "n_word","asd"],restrict=True)Result
content : I used to love having snowball fight with my friends and building snowmen on the streets around our neighborhood
Example 9: Extract a log in non-restricted mode
Raw log
content : I used to love having snowball fight with my friends and building snowmen on the streets around our neighborhoodTransformation rule
e_anchor("content","love * fight with my * and",["test1","test2","test13"],restrict=False)Result
content : I used to love having snowball fight with my friends and building snowmen on the streets around our neighborhood test1 : having snowball test2 : friends
Example 10: Extract one value and skip another
Raw log
content: Could you compare the severity of natural disasters to man-made disastersTransformation rule
e_anchor('content', 'compare the * of natural disasters to man-made *', 'n-word,*')Result
content : Could you compare the severity of natural disasters to man-made disasters n-word : severity