XpoLog Regular Expressions Patterns Language
As part of XpoLog parsing language, users may apply a regular expression on another column in order to extract a specific value from that column.
Regular expressions language:
CharactersÂ
x The character xÂ
\\ The backslash characterÂ
\0n The character with octal value 0n (0 <= n <= 7)Â
\0nn The character with octal value 0nn (0 <= n <= 7)Â
\0mnn The character with octal value 0mnn (0 <= m <= 3, 0 <= n <= 7)Â
\xhh The character with hexadecimal value 0xhhÂ
\uhhhh The character with hexadecimal value 0xhhhhÂ
\t The tab character ('\u0009')Â
\n The newline (line feed) character ('\u000A')Â
\r The carriage-return character ('\u000D')Â
\f The form-feed character ('\u000C')Â
\a The alert (bell) character ('\u0007')Â
\e The escape character ('\u001B')Â
\cx The control character corresponding to xÂ
Character classesÂ
[abc] a, b, or c (simple class)Â
[^abc] Any character except a, b, or c (negation)Â
[a-zA-Z] a through z or A through Z, inclusive (range)Â
[a-d[m-p]] a through d, or m through p: [a-dm-p] (union)Â
[a-z&&[def]] d, e, or f (intersection)Â
[a-z&&[^bc]] a through z, except for b and c: [ad-z] (subtraction)Â
[a-z&&[^m-p]] a through z, and not m through p: [a-lq-z](subtraction)Â
Predefined character classesÂ
. Any character (may or may not match line terminators)Â
\d A digit: [0-9]Â
\D A non-digit: [^0-9]Â
\s A whitespace character: [ \t\n\x0B\f\r]Â
\S A non-whitespace character: [^\s]Â
\w A word character: [a-zA-Z_0-9]Â
\W A non-word character: [^\w]Â
POSIX character classes (US-ASCII only)Â
\p{Lower} A lower-case alphabetic character: [a-z]Â
\p{Upper} An upper-case alphabetic character:[A-Z]Â
\p{ASCII} All ASCII:[\x00-\x7F]Â
\p{Alpha} An alphabetic character:[\p{Lower}\p{Upper}]Â
\p{Digit} A decimal digit: [0-9]Â
\p{Alnum} An alphanumeric character:[\p{Alpha}\p{Digit}]Â
\p{Punct} Punctuation: One of !"#$%&'()*+,-./:;<=>?@[\]^_`{|}~Â
\p{Graph} A visible character: [\p{Alnum}\p{Punct}]Â
\p{Print} A printable character: [\p{Graph}]Â
\p{Blank} A space or a tab: [ \t]Â
\p{Cntrl} A control character: [\x00-\x1F\x7F]Â
\p{XDigit} A hexadecimal digit: [0-9a-fA-F]Â
\p{Space} A whitespace character: [ \t\n\x0B\f\r]Â
Classes for Unicode blocks and categoriesÂ
\p{InGreek} A character in the Greek block (simple block)Â
\p{Lu} An uppercase letter (simple category)Â
\p{Sc} A currency symbolÂ
\P{InGreek} Any character except one in the Greek block (negation)Â
[\p{L}&&[^\p{Lu}]] Any letter except an uppercase letter (subtraction)Â
Boundary matchersÂ
^ The beginning of a lineÂ
$ The end of a lineÂ
\b A word boundaryÂ
\B A non-word boundaryÂ
\A The beginning of the inputÂ
\G The end of the previous matchÂ
\Z The end of the input but for the final terminator, if anyÂ
\z The end of the inputÂ
Greedy quantifiersÂ
? any character, once or not at allÂ
* any character, zero or more timesÂ
+ any character, one or more timesÂ
X{n} X, exactly n timesÂ
X{n,} X, at least n timesÂ
X{n,m} X, at least n but not more than m timesÂ
Reluctant quantifiersÂ
?? any character, once or not at allÂ
*? any character, zero or more timesÂ
+? any character, one or more timesÂ
X{n}? X, exactly n timesÂ
X{n,}? X, at least n timesÂ
X{n,m}? X, at least n but not more than m timesÂ
Possessive quantifiersÂ
?+ any character, once or not at allÂ
*+ any character, zero or more timesÂ
++ any character, one or more timesÂ
X{n}+ X, exactly n timesÂ
X{n,}+ X, at least n timesÂ
X{n,m}+ X, at least n but not more than m timesÂ
Logical operatorsÂ
XY X followed by YÂ
X|Y Either X or YÂ
(X) X, as a capturing groupÂ
Back referencesÂ
\n Whatever the nth capturing group matchedÂ
QuotationÂ
\ Nothing, but quotes the following characterÂ
\Q Nothing, but quotes all characters until \EÂ
\E Nothing, but ends quoting started by \QÂ
Special constructs (non-capturing)Â
(?:X) X, as a non-capturing groupÂ
(?idmsux-idmsux) Nothing, but turns match flags on - offÂ
(?idmsux-idmsux:X) X, as a non-capturing group with the given flags on - offÂ
(?=X) X, via zero-width positive lookaheadÂ
(?!X) X, via zero-width negative lookaheadÂ
(?<=X) X, via zero-width positive lookbehindÂ
(? (?>X) X, as an independent, non-capturing groupÂ
--------------------------------------------------------------------------------
Backslashes, escapes, and quotingÂ
The backslash character ('\') serves to introduce escaped constructs, as defined above, as well as to quote characters that otherwise would be interpreted as un-escaped constructs. Thus the expression \\ matches a single backslash.
One special case is right/left curly brackets since a curly bracket is used by XpoLog pattern syntax as a reserved sign to open/close field tags. To represent curly bracket which are not XpoLog reserved use: \u007B (left curly bracket) and \u007D (right curly bracket).
It is an error to use a backslash prior to any alphabetic character that does not denote an escaped construct; these are reserved for future extensions to the regular-expression language. A backslash may be used prior to a non-alphabetic character regardless of whether that character is part of an un-escaped construct.Â
Character ClassesÂ
Character classes may appear within other character classes, and may be composed by the union operator (implicit) and the intersection operator (&&). The union operator denotes a class that contains every character that is in at least one of its operand classes. The intersection operator denotes a class that contains every character that is in both of its operand classes.Â
The precedence of character-class operators is as follows, from highest to lowest:Â
1 Literal escape \xÂ
2 Grouping [...]Â
3 Range a-zÂ
4 Union [a-e][i-u]Â
5 Intersection [a-z&&[aeiou]]Â
Note that a different set of metacharacters are in effect inside a character class than outside a character class. For instance, the regular expression . loses its special meaning inside a character class, while the expression - becomes a range forming metacharacter.Â
Line terminatorsÂ
A line terminator is a one- or two-character sequence that marks the end of a line of the input character sequence. The following are recognized as line terminators:Â
A newline (line feed) character ('\n'),Â
A carriage-return character followed immediately by a newline character ("\r\n"),Â
A standalone carriage-return character ('\r'),Â
A next-line character ('\u0085'),Â
A line-separator character ('\u2028'), orÂ
A paragraph-separator character ('\u2029).Â
If UNIX_LINES mode is activated, then the only line terminators recognized are newline characters.Â
The regular expression . matches any character except a line terminator unless the DOTALL flag is specified.Â
By default, the regular expressions ^ and $ ignore line terminators and only match at the beginning and the end, respectively, of the entire input sequence. If MULTILINE mode is activated then ^ matches at the beginning of input and after any line terminator except at the end of input. When in MULTILINE mode $ matches just before a line terminator or the end of the input sequence.Â
For a more precise description of the behavior of regular expression constructs, please see Mastering Regular Expressions, 2nd Edition, Jeffrey E. F. Friedl, O'Reilly and Associates, 2002.Â
Syntax:
regexp - a regular expression, used to extract part of the data from another column will be extracted out of the value in the source column
 {regexp,refIndex=index | refName=column_name;columnType=date/timestamp/number;multiLine=true/false,(regular_expression_to_extract)} | refIndex/refName (mandatory): the zero-based index of the source column / the name of the source column columnType (mandatory for date/timestamp only): multiLine (optional): indicates whether the record spreads over more than one line |
Â
Examples:
Log Events Example | XpoLog Pattern | What will be extracted by the |
---|---|---|
Mon Jul 10 04:33:51 2017 ALTER DATABASE ADD LOGFILE THREAD 2 GROUP 3 ('/oradata/PROD/redo.log') SIZE 200K, GROUP 4 ('/oradata/PROD/redo.log') SIZE 200K | {date:Date,EEE MMM dd HH:mm:ss yyyy}{regexp:Error Code,refName=Message,(ORA-\d+)}{string:Message} | ORA-336 Â will be extracted to a unique column |
Log Message: Error in Application at <2017-05-05 12:00:00.000> | {text:type}:{string:Message}{regexp:Date,refName=Message;columnType=date;dateFormat=yyyy-MM-dd HH:mm:ss.SSS,<(\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d\.\d\d\d)>} | 2017-05-05 12:00:00.000 will be extracted to a unique column of type date |
Log Message: Error in Application at <1399291200000> | {text:type}:{string:Message}{regexp:Timestamp,refName=Message;columnType=timestamp;dateFormat=yyyy-MM-dd HH:mm:ss.SSS,<(\d+)>} | 2017-05-05 12:00:00.000 will be extracted to a unique column of type date (which is a translation of the timestamp 1399291200000) |
2017-05-05 12:00:00.000 ERROR Failed to run application, x=1 | {date,yyyy-MM-dd HH:mm:ss.SSS} {text:Priority} {string:Message}{regexp:Error-Code,refName=Message,((x=)|(y=)|(z=))(\s*)[XPLG_PARAM(\d+)]} | This regular expression looks for numbers either after 'x=' / 'y=' / 'z=' and will extract the result under a unique column |
2017-05-05 12:00:00.000 ERROR Invalid Processing Time: 875ms | {date,yyyy-MM-dd HH:mm:ss.SSS} {text:Priority} {string:Message}{regexp:Processing-Time,refName=Message;columnType=number,Processing Time: (\d+)} | 875 will be extracted to a unique column of type number |
2017-05-05 12:00:00.000 ERROR Message = "userCode":{"XXXX":"YYYYYY"} | {date,yyyy-MM-dd HH:mm:ss.SSS} {text:Priority} {string:Message}{regexp:Code-X,refName=Message,"userCode":\u007B"([^"]*)}{regexp:Code-Y,refName=Message,"userCode":\u007B"\w+":"([^"]*)} | XXXX will be extracted to a a unique column (Code-X) Â YYYYYY will be extracted to a a unique column (Code-Y) |
Â