Search expression
nvpair:path=C:\\Program\ Files
Matches
C:\Program Files
Searching in a specific part of the message
You can search in a specific part of the message using the
<type>:
prefix. The
message:
(or
msg:
) prefix means the message part and can be omitted. For example, use the
program:
prefix to search for the name of an application, or use the
host:
prefix to search for a host
name, and so on.
Example: Searching specific parts of messages
Search expression
program:syslog-ng
Matches
All log messages from the syslog-ng application.
Searching the name-value pairs of the message
You can search the structured data part of log messages using the
nvpair:
prefix. Use the
=
delimiter to separate the name and the value of structured data parameters, and remove
the quote marks from the values.
Example: Searching the structured data part of messages
Search
expression
nvpair:[email protected]_type=Alert
Matches
All log messages where there is a [email protected] element with the
event_type="Alert" parameter. For example:
[[email protected] EVENT_TYPE="Alert"]
Example: Using wildcard * to search the structured data
You can use the asterisk (
*
) wildcard to broaden the search to all structured
data elements.
SSB 5.3.0 User Guide
Searching log messages
25