All Products
Search
Document Center

Simple Log Service:Value extraction functions

Last Updated:Aug 26, 2026

This topic explains the syntax of field value extraction functions, including their parameters and examples.

Function list

Type

Function

Description

Regular expression extraction

e_regex

Extracts a value from a field using a regular expression and assigns it to another field.

This function can be combined with other functions. For a related example, see Parse Java error logs.

JSON extraction

e_json

Processes a JSON object in a specified field. Operations include expanding the object, extracting data with JMESPath, or extracting and expanding.

This function can be combined with other functions. For a related example, see Transform complex JSON data.

Delimiter-based extraction

e_csv, e_psv, e_tsv

Extracts values for multiple fields from a source field using a delimiter and predefined field names.

  • e_csv: The default delimiter is a comma (,).

  • e_psv: The default delimiter is a vertical bar (|).

  • e_tsv: The default delimiter is a tab character (\t).

These functions can be combined with other functions. For a related example, see Parse CSV-formatted logs.

Key-value extraction

e_kv

Extracts key-value pairs from one or more source fields using a specified quote character.

This function can be combined with other functions. For a related example, see Extract dynamic key-value pairs from a string.

e_kv_delimit

Extracts key-value pairs from a source field using a delimiter.

Syslog standard extraction

e_syslogrfc

Calculates facility and severity from a priority value based on the Syslog protocol and maps them to the corresponding level.

This function can be combined with other functions. For a related example, see Parse standard Syslog format data.

Rule-based extraction

e_anchor

Extracts strings using the rules defined in anchor_rules.

e_regex

Extracts values from a field based on a regular expression and assigns them to other fields.

  • Syntax

    e_regex(key, regex, fields_info, mode="fill-auto", pack_json=None)
  • Parameters

    Parameter

    Type

    Required

    Description

    key

    Any

    Yes

    The source field. If the field does not exist, the function does nothing. For information about how to configure special field names, see event types.

    regex

    String

    Yes

    The regular expression used to extract field values. It supports both capturing and non-capturing groups.

    Note

    A non-capturing group, which requires the ?: prefix, is sometimes used for grouping. For example, \w+@\w+\.\w(?:\.\cn)?. For more information, see non-capturing groups.

    fields_info

    String/List/Dict

    No

    The target fields for the matched values. This parameter is required if you do not use named capturing groups in the regular expression.

    mode

    String

    No

    The overwrite mode for the fields. The default value is fill-auto. For more information about the values and their meanings, see field extraction check and overwrite mode.

    pack_json

    String

    No

    Packs all matched results from the regular expression into the field specified by pack_json. The default value is None, which indicates that packing is disabled.

  • Response

    Returns the log, updated with the extracted fields and their values.

  • Examples

    • Example 1: Extract a single value

      • raw log

        msg: 192.168.0.1 http://... 127.0.0.0
      • transformation rule

        # Extract the first IP address from the msg field. 
        e_regex("msg",r"\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}","ip")
      • transformation result

        msg: 192.168.0.1 http://... 127.0.0.0
        ip: 192.168.0.1
    • Example 2: Extract multiple values

      • raw log

        msg: 192.168.0.1 http://... 127.0.0.0
      • transformation rule

        # Extract two IP addresses from the msg field and assign them to server_ip and client_ip.
        e_regex("msg",r"\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}",["server_ip","client_ip"])
      • transformation result

        msg: 192.168.0.1 http://... 127.0.0.0
        server_ip: 192.168.0.1
        client_ip: 127.0.0.0
    • Example 3: Extract values by using a capturing group.

      • raw log

        content: start sys version: deficience, err: 2
      • transformation rule

        # Use a regular expression to capture the version and error values from the content field.
        e_regex("content",r"start sys version: (\w+),\s*err: (\d+)",["version","error"])
      • transformation result

        content: start sys version: deficience, err: 2
        error: 2
        version: deficience
    • Example 4: Extract values by using a named capturing group

      • raw log

        content:  start sys version: deficience, err: 2
      • transformation rule

        e_regex("content",r"start sys version: (?P<version>\w+),\s*err: (?P<error>\d+)")
      • transformation result

        content:  start sys version: deficience, err: 2
        error:  2
        version:  deficience
    • Example 5: Dynamically create a field name and value from the dict field.

      • raw log

        dict: verify:123
      • transformation rule

        e_regex("dict",r"(\w+):(\d+)",{r"k_\1": r"v_\2"})
      • transformation result

        dict: verify:123
        k_verify: v_123
    • Example 6: Extract and pack a value into the name field.

      • raw log

        msg: 192.168.0.1 http://... 127.0.0.0
      • transformation rule

        e_regex("msg", r"\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}", "ip", pack_json="name")
      • transformation result

        msg:192.168.0.1 http://... 127.0.0.0
        name:{"ip": "192.168.0.1"}
    • Example 7: Dynamically create fields from the dict field and pack them into the name field.

      • raw log

        dict: x:123, y:456, z:789
      • transformation rule

        e_regex("dict", r"(\w+):(\d+)", {r"k_\1": r"v_\2"}, pack_json="name")
      • transformation result

        dict:x:123, y:456, z:789
        name:{"k_x": "v_123", "k_y": "v_456", "k_z": "v_789"}
    • Example 8: Extract and pack values from a capturing group into the name field.

      • raw log

        content: start sys version: deficience, err: 2
      • transformation rule

        e_regex( "content", r"start sys version: (\w+),\s*err: (\d+)", ["version", "error"],pack_json="name")
      • transformation result

        content:start sys version: deficience, err: 2
        name:{"version": "deficience", "error": "2"}
  • References

    You can combine this function with other functions. For a related example, see Parse Java error logs.

e_json

Performs JSON operations on a JSON object in a specified field. These operations include expanding the JSON data, extracting data with a JMESPath expression, or extracting and then expanding a JSON subset.

  • Syntax

    e_json(key, expand=None, depth=100, prefix="__", suffix="__", fmt="simple", sep=".", 
         expand_array=True, fmt_array="{parent}_{index}", 
         include_node=r"[\u4e00-\u9fa5\u0800-\u4e00a-zA-Z][\w\-\.]*",  
         exclude_node="", include_path="", exclude_path="",
         jmes="", output="", jmes_ignore_none=False, mode='fill-auto'
    )
    Note

    If the target string is not a valid JSON object, the e_json function returns the original string without parsing it.

  • Parameters

    Parameter

    Type

    Required

    Description

    key

    String

    Yes

    The name of the input field. If the field does not exist, the function does nothing. For information about how to configure special field names, see Event types.

    expand

    Boolean

    No

    Specifies whether to expand the field.

    • If the jmes parameter is not configured, the default value is True, which expands the field.

    • If the jmes parameter is configured, the default value is False, which does not expand the field.

    depth

    Number

    No

    The depth to which the function expands the field. Valid values: 1 to 2000. The default value is 100. A value of 1 expands only the first level.

    prefix

    String

    No

    The prefix to add to each expanded field name.

    suffix

    String

    No

    The suffix to add to each expanded field name.

    fmt

    String

    No

    The formatting method for expanded field names. Valid values:

    • simple (default): Uses the current node name as the field name. The format is {prefix}{current}{suffix}.

    • full: Combines the full path from the source field to the current node as the field name. The format is {parent_list_str}{sep}{prefix}{current}{suffix}. The delimiter is specified by the sep parameter. The default delimiter is ..

    • parent: Combines the current node name with its immediate parent node name. The format is {parent}{sep}{prefix}{current}{suffix}. The delimiter is specified by the sep parameter. The default delimiter is ..

    • root: Combines the current node name with the root node name. The format is {parent_list[0]}{sep}{prefix}{current}{suffix}. The delimiter is specified by the sep parameter. The default delimiter is ..

    sep

    String

    No

    The delimiter between parent and child node names. This parameter applies when fmt is set to full, parent, or root. The default value is ..

    expand_array

    Boolean

    No

    Specifies whether to expand arrays. The default value is True.

    fmt_array

    String

    No

    The formatting method for array expansion. The format is {parent_rlist[0]}_{index}. You can also build a custom format string by using up to five placeholders: parent_list, current, sep, prefix, and suffix.

    include_node

    String/Number

    No

    The node allowlist specifies the node names to include for filtering. By default, only nodes whose names consist of Chinese characters, digits, letters, and _.- are automatically expanded.

    exclude_node

    String

    No

    A regular expression that defines a blacklist of node names to exclude.

    include_path

    String

    No

    A regular expression that defines a whitelist of node paths to include.

    exclude_path

    String

    No

    A regular expression that defines a blacklist of node paths to exclude.

    jmes

    String

    No

    A JMESPath expression to extract data from the JSON object.

    output

    String

    No

    The name of the output field for the value extracted using the JMESPath expression.

    jmes_ignore_none

    Boolean

    No

    Specifies the behavior when the JMESPath expression finds no value. If True (the default), the extraction is ignored. If False, an empty string is returned.

    mode

    String

    No

    The field overwrite mode. The default value is fill-auto. For more information, see Field extraction check and overwrite modes.

    • JSON expansion filtering

      • If a node whitelist is set, only nodes in the whitelist are included in the result. Example regular expression for a node whitelist: e_json("json_data_filed", ...., include_node=r'key\d+').

      • If a node blacklist is set, nodes in the blacklist are excluded from the result. Example regular expression for a node blacklist: e_json("json_data_filed", ...., exclude_node=r'key\d+').

      • For node path expansion, the include_path and exclude_path regular expressions are matched against the start of the path. Node paths use . as the delimiter.

    • JMESPath filtering

      Use JMESPath to select and compute data.

      • Select a list of element attributes from a specific JSON path: e_json(..., jmes="cve.vendors[*].product",output="product")

      • Concatenate element attributes from a specific JSON path with a comma (,): e_json(..., jmes="join(',', cve.vendors[*].name)",output="vendors")

      • Calculate the maximum attribute value for elements in a specific JSON path: e_json(..., jmes="max(words[*].score)",output="hot_word")

      • Return an empty string if a specific path does not exist or is empty: e_json(..., jmes="max(words[*].score)",output="hot_word", jmes_ignore_none=False)

    • parent_list and parent_rlist

      The following examples demonstrate their usage.

      Raw log:

      data: { "k1": 100,"k2": {"k3": 200,"k4": {"k5": 300}}}
      • parent_list arranges parent nodes from left to right.

        e_json("data", fmt='{parent_list[0]}-{parent_list[1]}#{current}')

        Transformation result:

        data:{ "k1": 100,"k2": {"k3": 200,"k4": {"k5": 300}}}
        data-k2#k3:200
        data-k2#k5:300
      • parent_rlist arranges parent nodes from right to left.

        e_json("data", fmt='{parent_rlist[0]}-{parent_rlist[1]}#{current}')

        Transformation result:

        data:{ "k1": 100,"k2": {"k3": 200,"k4": {"k5": 300}}}
        k2-data#k3:200
        k4-k2#k5:300
  • Response

    Returns the log with the newly added fields.

  • Examples

    • Example 1: Expanding a field.

      • Raw log

        data: {"k1": 100, "k2": 200}
      • Transformation rule

        e_json("data",depth=1)
      • Transformation result

        data: {"k1": 100, "k2": 200}
        k1: 100
        k2: 200
    • Example 2: Adding a prefix and a suffix to field names.

      • Raw log

        data: {"k1": 100, "k2": 200}
      • Transformation rule

        e_json("data", prefix="data_", suffix="_end")
      • Transformation result

        data: {"k1": 100, "k2": 200}
        data_k1_end: 100
        data_k2_end: 200
    • Example 3: Expanding a field using different formats.

      • Raw log

        data: {"k1": 100, "k2": {"k3": 200, "k4": {"k5": 300} } }
      • fmt=full

        e_json("data", fmt='full')
        data: {"k1": 100, "k2": {"k3": 200, "k4": {"k5": 300} } }
        data.k1: 100
        data.k2.k3: 200
        data.k2.k4.k5: 300
      • fmt=parent

        e_json("data", fmt='parent')
        data: {"k1": 100, "k2": {"k3": 200, "k4": {"k5": 300} } }
        data.k1: 100
        k2.k3: 200
        k4.k5: 300
      • fmt=root

        e_json("data", fmt='root')
        data: {"k1": 100, "k2": {"k3": 200, "k4": {"k5": 300} } }
        data.k1: 100
        data.k3: 200
        data.k5: 300
    • Example 4: Extracting JSON data with a specified delimiter, prefix, and suffix.

      • Raw log

        data: {"k1": 100, "k2": {"k3": 200, "k4": {"k5": 300} } }
      • Transformation rule

        e_json("data", fmt='parent', sep="@", prefix="__", suffix="__")
      • Transformation result

        data: {"k1": 100, "k2": {"k3": 200, "k4": {"k5": 300} } }
        data@__k1__:100
        k2@__k3__:200
        k4@__k5__:300
    • Example 5: Using the fmt_array parameter to extract JSON data as an array.

      • Raw log

        people: [{"name": "xm", "sex": "boy"}, {"name": "xz", "sex": "boy"}, {"name": "xt", "sex": "girl"}]
      • Transformation rule

        e_json("people", fmt='parent', fmt_array="{parent_rlist[0]}-{index}")
      • Transformation result

        people: [{"name": "xm", "sex": "boy"}, {"name": "xz", "sex": "boy"}, {"name": "xt", "sex": "girl"}]
        people-0.name: xm
        people-0.sex: boy
        people-1.name: xz
        people-1.sex: boy
        people-2.name: xt
        people-2.sex: girl
    • Example 6: Using a JMESPath expression to extract a JSON object.

      • Raw log

        data: { "people": [{"first": "James", "last": "d"},{"first": "Jacob", "last": "e"}],"foo": {"bar": "baz"}}
      • Transformation rule

        e_json("data", jmes='foo', output='jmes_output0')
        e_json("data", jmes='foo.bar', output='jmes_output1')
        e_json("data", jmes='people[0].last', output='jmes_output2')
        e_json("data", jmes='people[*].first', output='jmes_output3')
      • Transformation result

        data: { "people": [{"first": "James", "last": "d"},{"first": "Jacob", "last": "e"}],"foo": {"bar": "baz"}}
        jmes_output0: {"bar": "baz"}
        jmes_output1: baz
        jmes_output2: d
        jmes_output3: ["James", "Jacob"]
  • Further reading

    For an example of combining this function with others, see Complex JSON data transformation.

e_csv, e_psv, and e_tsv

These functions extract multiple fields from a specified field using a custom delimiter and predefined field names.

  • e_csv: The default delimiter is a comma (,).

  • e_psv: The default delimiter is a vertical bar (|).

  • e_tsv: The default delimiter is a tab character (\t).

  • Syntax

    e_csv(input field name, output field list, sep=",", quote='"', restrict=True, mode="fill-auto")
    e_psv(input field name, output field list, sep="|", quote='"', restrict=True, mode="fill-auto")
    e_tsv(input field name, output field list, sep="\t", quote='"', restrict=True, mode="fill-auto")
  • Parameters

    Parameter

    Type

    Required

    Description

    input field name

    Any

    Yes

    The name of the input field. If the specified field does not exist, the function takes no action. For information about how to specify special field names, see Event types.

    output field list

    Any

    Yes

    The names of the output fields that store the parsed values.

    You can provide the names as a list of strings, such as ["error", "message", "result"].

    If the field names do not contain commas, you can also provide a single string with names separated by commas, such as "error, message, result".

    For information about how to specify special field names, see Event types.

    sep

    String

    No

    The delimiter. It must be a single character.

    quote

    String

    No

    The character used to enclose values. Use this when a value contains the delimiter.

    restrict

    Boolean

    No

    Specifies whether to use restricted mode. The default value is True, which enables restricted mode. This parameter determines the behavior when the number of parsed values does not match the number of output fields:

    • In restricted mode (True), the function takes no action.

    • In non-restricted mode (False), the function assigns values to the matching fields.

    mode

    String

    No

    The field overwrite mode. The default value is fill-auto. For more information about the values and their meanings, see Field extraction check and overwrite modes.

  • Response

    Returns the log with the new fields added.

  • Examples

    The following example uses e_csv. The e_psv and e_tsv functions operate similarly.

    • Raw log

      content: 192.168.0.100,10/Jun/2019:11:32:16 +0800,example.aliyundoc.com,GET /zf/11874.html HTTP/1.1,200,0.077,6404,192.168.0.100:8001,200,0.060,https://image.developer.aliyundoc.com/s?q=how-to-make-noodles&from=wy878378&uc_param_str=dnntnwvepffrgibijbprsvdsei,-,Mozilla/5.0 (Linux; Android 9; HWI-AL00 Build/HUAWEIHWI-AL00) AppleWebKit/537.36,-,-
    • Transformation rule

      e_csv("content", "remote_addr, time_local,host,request,status,request_time,body_bytes_sent,upstream_addr,upstream_status, upstream_response_time,http_referer,http_x_forwarded_for,http_user_agent,session_id,guid")
    • Result

      content:  192.168.0.100,10/Jun/2019:11:32:16 +0800,example.aliyundoc.com,GET /zf/11874.html HTTP/1.1,200,0.077,6404,192.168.0.100:8001,200,0.060,https://image.developer.aliyundoc.com/s?q=how-to-make-noodles&from=wy878378&uc_param_str=dnntnwvepffrgibijbprsvdsei,-,Mozilla/5.0 (Linux; Android 9; HWI-AL00 Build/HUAWEIHWI-AL00) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Mobile Safari/537.36,-,-
        body_bytes_sent:  6404
      guid:  -
      host:  example.aliyundoc.com
      http_referer:  https://image.developer.aliyundoc.com/s?q=how-to-make-noodles&from=wy878378&uc_param_str=dnntnwvepffrgibijbprsvdsei
      http_user_agent:  Mozilla/5.0 (Linux; Android 9; HWI-AL00 Build/HUAWEIHWI-AL00) AppleWebKit/537.36
      http_x_forwarded_for:  -
      remote_addr:  192.168.0.100
      request:  GET /zf/11874.html HTTP/1.1
      request_time:  0.077
      session_id:  -
      status:  200
      time_local:  10/Jun/2019:11:32:16 +0800
      topic:  syslog-forwarder
      upstream_addr:  192.168.0.100:8001
      upstream_response_time:  0.060
      upstream_status:  200
  • More information

    These functions can be combined with other functions. For a related example, see Parse CSV-formatted logs.

e_kv

Extracts key-value pairs from one or more input fields.

  • Syntax

    e_kv(field_or_list, sep="=", quote='"', escape=False, prefix="", suffix="", mode="fill-auto")
  • Parameters

    Parameter

    Type

    Required

    Description

    field_or_list

    String or list of strings

    Yes

    The name of one or more input fields. For information about how to specify special field names, see Event types.

    sep

    String

    No

    The key-value separator, which can be a regular expression. The default value is =.

    Note

    You can use non-capturing groups, but not capturing groups. For more information, see Grouping.

    quote

    String

    No

    The character used to enclose values. The default value is ".

    Note

    The value of an extracted dynamic key-value pair is typically enclosed in quotation marks, for example, a="abc" and b="xyz". If a value is not enclosed in quotation marks, the system extracts only a value that consists of the following characters: Chinese characters, letters, numbers, and the symbols _-.%~. For example, from a=ab12_-.%~|abc b=123, the system extracts a: ab12_-.%~ and b: 123.

    escape

    Boolean

    No

    Controls whether to interpret escape characters in values. The default value is False. For example, from the input key="abc\"xyz", by default, the function extracts the value abc\ for the key field. If you set escape=True, the extracted value is abc"xyz.

    prefix

    String

    No

    The prefix to add to the names of extracted fields.

    suffix

    String

    No

    The suffix to add to the names of extracted fields.

    mode

    String

    No

    The field overwrite mode. The default value is fill-auto. For more information about available modes, see Field extraction check and overwrite modes.

  • Response

    Adds the extracted key-value pairs to the log as new fields.

  • Examples

    • Example 1: Extract key-value pairs using the default delimiter =.

      • Raw log

        http_refer: https://video.developer.aliyundoc.com/s?q=asd&a=1&b=2
        Note

        If the raw log is request_uri: a1=1&a2=&a3=3 and the value of a2 is empty, the e_kv() function cannot extract a2. You can use the e_regex() function to extract it, for example, e_regex("request_uri",r'(\w+)=([^=&]*)',{r"\1":r"\2"},mode="overwrite").

      • Transformation rule

        e_kv("http_refer")
      • Result

        http_refer: https://video.developer.aliyundoc.com/s?q=asd&a=1&b=2
        q: asd
        a: 1
        b: 2
    • Example 2: Add a prefix and a suffix to field names.

      • Raw log

        http_refer: https://video.developer.aliyundoc.com/s?q=asd&a=1&b=2
      • Transformation rule

        e_kv(
            "http_refer",
            sep="=",
            quote='"',
            escape=False,
            prefix="data_",
            suffix="_end",
            mode="fill-auto",
        )
      • Result

        http_refer: https://video.developer.aliyundoc.com/s?q=asd&a=1&b=2
        data_q_end: asd
        data_a_end: 1
        data_b_end: 2
    • Example 3: Extract key-value pairs from the content2 field and interpret escape characters using the escape parameter.

      • Raw log

        content2: k1:"v1\"abc", k2:"v2", k3: "v3"
      • Transformation rule

        e_kv("content2", sep=":", escape=True)
      • Result

        content2:  k1:"v1\"abc", k2:"v2", k3: "v3"
        k1: v1"abc
        k2: v2
        k3: v3
  • Further reading

    For an example of combining this function with others, see Extract dynamic key-value pairs from a string.

e_kv_delimit

Extracts key-value pairs from an input field by using delimiters.

  • Syntax

    e_kv_delimit(field_or_list, pair_sep=r"\s", kv_sep="=", prefix="", suffix="", mode="fill-auto")
  • Parameters

    Parameter

    Type

    Required

    Description

    field_or_list

    string or list of strings

    Yes

    The name of one or more input fields. For information about how to specify special field names, see event type.

    pair_sep

    string

    No

    A regular expression that separates key-value pairs. The default value is \s. Other examples include \s\w and abc\s.

    Note

    To use a literal string as a separator, we recommend first replacing it with a single-character delimiter by using the str_replace or regex_replace function. You can then use this function to parse the field.

    kv_sep

    string

    No

    A regular expression that separates a key from its value. The default value is =. The expression is not limited to a single character.

    Note

    You can use non-capturing groups, but not capturing groups. For more information, see Grouping.

    prefix

    string

    No

    The prefix to add to the extracted field names.

    suffix

    string

    No

    The suffix to add to the extracted field names.

    mode

    string

    No

    The field overwrite mode. The default value is fill-auto. For details about the values, see Field extraction check and overwrite modes.

  • Response

    Returns the log with the extracted key-value pairs added as new fields.

  • Examples

    • Example 1: Extracting key-value pairs using the default delimiter =.

      • Raw log

        data: i=c1 k1=v1 k2=v2 k3=v3
        Note

        If the raw log is request_uri: a1=1&a2=&a3=3, the e_kv_delimit() function cannot extract a2 because its value is empty. To extract pairs with empty values, use the e_regex() function. For example: e_regex("request_uri",r'(\w+)=([^=&]*)',{r"\1":r"\2"}, mode="overwrite").

      • Transformation rule

        e_kv_delimit("data")
      • Result

        data: i=c1 k1=v1 k2=v2 k3=v3
        i: c1
        k2: v2
        k1: v1
        k3: v3
    • Example 2: Extract key-value pairs by using the delimiter &?.

      • Raw log

        data: k1=v1&k2=v2?k3=v3
      • Transformation rule

        e_kv_delimit("data",pair_sep=r"&?")
      • Result

        data: k1=v1&k2=v2?k3=v3
        k2: v2
        k1: v1
        k3: v3
    • Example 3: Extract key-value pairs by using a regular expression as the key-value separator.

      • Raw log

        data: k1=v1 k2:v2 k3=v3
      • Transformation rule

        e_kv_delimit("data", kv_sep=r"(?:=|:)")
      • Result

        data: k1=v1 k2:v2 k3=v3
        k2: v2
        k1: v1
        k3: v3

e_syslogrfc

Calculates the facility and severity from a priority value according to the syslog protocol and adds the corresponding labels.

  • Syntax

    e_syslogrfc(key, rfc, fields_info=None, mode='overwrite')
  • Parameters

    Parameter

    Type

    Required

    Description

    key

    Any

    Yes

    The name of the field that contains the priority value.

    rfc

    String

    Yes

    The syslog protocol to use. Valid values: SYSLOGRFC3164 and SYSLOGRFC5424.

    fields_info

    Dict

    No

    A dictionary that maps default output field names (keys) to custom names (values). The following fields can be renamed: {"_severity_":"sev","_facility_":"fac","_severitylabel_":"sevlabel","_facilitylabel_":"faclabel"}

    mode

    String

    No

    The overwrite mode for the output fields. The default value is overwrite. For more information, see Field extraction check and overwrite modes.

  • Response

    Returns the log with the new facility, severity, and label fields.

  • Examples

    • Example 1: Extract facility, severity, and label information using the SYSLOGRFC5424 protocol.

      • raw log

        receive_time: 1558663265
        _priority_: 13
        _version_: 1
        _log_time_: 2019-05-06 11:50:16.015554+08:00
        _hostname_: iZbp1a65********i2qZ
        _program_: root
        _procid_: -
        _msgid_: -
        _extradata_: -
        _content_: twish
      • transformation rule

        e_syslogrfc("_priority_","SYSLOGRFC5424")
      • Result

        receive_time: 1558663265
        _priority_: 13
        _version_: 1
        _log_time_: 2019-05-06 11:50:16.015554+08:00
        _hostname_: iZbp1a65********i2qZ
        _program_: root
        _procid_: -
        _msgid_: -
        _extradata_: -
        _content_: twish
        _facility_: 1
        _severity_: 5
        _severitylabel_: Notice: normal but significant condition
        _facilitylabel_: user-level messages
    • Example 2: Extract facility, severity, and label information using the SYSLOGRFC5424 protocol and rename the output fields.

      • raw log

        receive_time: 1558663265
        _priority_: 13
        _version_: 1
        _log_time_: 2019-05-06 11:50:16.015554+08:00
        _hostname_: iZbp1a65********i2qZ
        _program_: root
        _procid_: -
        _msgid_: -
        _extradata_: -
        _content_: twish
      • transformation rule

        e_syslogrfc(
            "_priority_",
            "SYSLOGRFC5424",
            {
                "_facility_": "fac",
                "_severity_": "sev",
                "_facilitylabel_": "_facility_label_",
                "_severitylabel_": "_severity_label_",
            },
        )
      • Result

        receive_time: 1558663265
        _priority_: 13
        _version_: 1
        _log_time_: 2019-05-06 11:50:16.015554+08:00
        _hostname_: iZbp1a65********i2qZ
        _program_: root
        _procid_: -
        _msgid_: -
        _extradata_: -
        _content_: twish
        fac: 1
        sev: 5
        _severity_label_: Notice: normal but significant condition
        _facility_label_: user-level messages
  • References

    This function can be combined with other functions. For a related example, see Parse standard Syslog format data.

e_anchor

Extracts strings from an input field using rules you define in the anchor_rules parameter.

  • Syntax

    e_anchor(key,anchor_rules,fields,restrict=False,mode="overwrite")
  • Parameters

    Parameter

    Type

    Required

    Description

    key

    Any

    Yes

    The name of the input field.

    anchor_rules

    String

    Yes

    Defines the pattern to extract strings, where an asterisk (*) represents the content to be extracted. For example: User = *; Severity = *;.

    The logs displayed on the console are in a Key : Value format with a default space between the colon and the value. When you specify anchor_rules, do not include this space. In the sample log entry, the content field is the target field to be extracted.

    _source_:  bin-hangzhou-oss
    _tag_:_object_:  test001/test001-or20190906155735.perf
    _tag_:_receive_time_:  1582768681
    _topic_:
    content:  "Download": 4001792
    Note

    An asterisk (*) cannot be used as a prefix or suffix in the value of the input field.

    fields

    Any

    Yes

    The names of the output fields for the extracted values. You can specify the names as a list of strings, such as ["user", "job", "result"]. If the field names do not contain commas (,), you can also specify them as a single string with names separated by commas, such as "user, job, result". For details on specifying special field names, which can contain special characters but not asterisks (*), see event type.

    You can skip a field name by using an asterisk (*). For example, if you specify "user,*,result", only the user and result fields are created. For more information, see Example 10.

    restrict

    Boolean

    No

    Specifies whether to use restricted mode. The default is False (non-restricted mode). This parameter determines the behavior when the number of extracted values does not match the number of output fields:

    • In restricted mode (True), the function takes no action.

    • In non-restricted mode (False), the function assigns values to the corresponding fields in sequence.

    mode

    String

    No

    The default value is overwrite. See field extraction check and overwrite mode for more information.

  • Response

    Returns the original log with the extracted fields and their values appended.

  • Examples

    • Example 1: Extract multiple values

      • Raw log

        content : "Aug 2 04:06:08: host=192.168.0.10: local/ssl2 notice mcpd[3772]: User=jsmith@example.com: severity=warning: 01070638:5: Pool member 172.31.51.22:0 monitor status down."
      • Transformation rule

        e_anchor("content","User=*: severity=*:",["user_field","severity_field"])
      • Result

        content : "Aug 2 04:06:08: host=192.168.0.10: local/ssl2 notice mcpd[3772]: User=jsmith@example.com: severity=warning: 01070638:5: Pool member 172.31.51.22:0 monitor status down."
        user_field : jsmith@example.com
        severity_field : warning
    • Example 2: Extract multiple JSON array values

      • Raw log

        content : '"information":{"name_list":["Twiss","Evan","Wind","like"],"university":["UCL","Stanford University","CMU"]},"other":"graduate"'
      • Transformation rule

        e_anchor("content",'name_list":*,"university":*},', ["name_list","universities"])
      • Result

        content : '"information":{"name_list":["Twiss","Evan","Wind","like"],"university":["UCL","Stanford University","CMU"]},"other":"graduate"'
        name_list : ["Twiss","Evan","Wind","like"]
        universities : ["UCL","Stanford University","CMU"]
    • Example 3: Extract from a log that contains special characters

      • Raw log

        content : (+2019) June 24 "I am iron man"
      • Transformation rule

        e_anchor("content", "(+*) * \"*\"",["Year","Date","Msg"])
      • Result

        content : (+2019) June 24 "I am iron man"
        Year : 2019
        Date : June 24
        Msg : I am iron man
    • Example 4: Extract from a log that contains an invisible control character (\x09)

      • Raw log

        content : \x09\x09\x09Chrome/55.0 Safari/537.36
      • Transformation rule

        e_anchor("content", "\x09\x09\x09*/55.0 */537.36",["Google", "Apple"])
      • Result

        content : \x09\x09\x09Chrome/55.0 Safari/537.36
        Google : Chrome
        Apple : Safari
    • Example 5: Extract the content field, which contains a value with special characters. The field's value is To...Subject, which follows MESSAGE:.

      • Raw log

        content : 12:08:10,651 INFO sample_server ReportEmailer:178 - DEBUG SENDING MESSAGE: 
        To: example@aliyun.com
        Subject: New line Breaks in Message
      • Transformation rule

        e_anchor("content","* INFO *: \n    To: *\n    Subject: *",["time","message","email","subject"])
      • Result

        content : 12:08:10,651 INFO sample_server ReportEmailer:178 - DEBUG SENDING MESSAGE: 
        To: example@aliyun.com
        Subject: New line Breaks in Message
        time : 12:08:10,651
        message : sample_server ReportEmailer:178 - DEBUG SENDING MESSAGE
        email : example@aliyun.com
        subject : New line Breaks in Message
    • Example 6: Extract the content field, which contains a value with the invisible special character \t.

      • Raw log

        content :   I'm tabbed in
      • Transformation rule

        e_anchor("content","\tI'm * in","word")
        # You can also copy the exact value from the content field to create the pattern.
        # Do not copy the default space after the colon in the field name.
        e_anchor("content","    I'm * in","word")
      • Result

        content :   I'm tabbed in
        word : tabbed
    • Example 7: Extract the field content that contains a special character value, which is displayed as \t.

      • Raw log

        content : \tI'm tabbed in
      • Transformation rule

        e_anchor("content","\tI'm * in","word")
        # You can also use the following rule:
        e_anchor("content","    I'm * in","word")
      • Result

        content : \tI'm tabbed in
        word : tabbed
    • Example 8: Extract a log in restricted mode

      • Raw log

        content :  I used to love having snowball fight with my friends and building snowmen on the streets around our neighborhood
      • Transformation rule

        e_anchor("content","I * to * having",["v_word", "n_word","asd"],restrict=True)
      • Result

        content : I used to love having snowball fight with my friends and building snowmen on the streets around our neighborhood
    • Example 9: Extract a log in non-restricted mode

      • Raw log

        content :  I used to love having snowball fight with my friends and building snowmen on the streets around our neighborhood
      • Transformation rule

        e_anchor("content","love * fight with my * and",["test1","test2","test13"],restrict=False)
      • Result

        content : I used to love having snowball fight with my friends and building snowmen on the streets around our neighborhood
        test1 : having snowball
        test2 : friends
    • Example 10: Extract one value and skip another

      • Raw log

        content: Could you compare the severity of natural disasters to man-made disasters
      • Transformation rule

        e_anchor('content', 'compare the * of natural disasters to man-made *', 'n-word,*')
      • Result

        content : Could you compare the severity of natural disasters to man-made disasters
        n-word : severity