---
name: azion-filter-events
description: >-
  Narrow a Real-Time Events search with the Filter by field, using the key and value syntax it accepts and the wildcards that widen a match.
---

# Filter events

You can narrow a [Real-Time Events](/en/documentation/platform/real-time-events/) search with the **Filter by** field in Azion Console, so the result holds only the records that carry the values you name. **Filter by** is a control of the classic view, which is the view Real-Time Events opens on.

A filter names a variable and a value. The variables a data source carries, and the values each one accepts, therefore decide what a search can match. For both, refer to [Data sources](/en/documentation/platform/real-time-events/data-sources/).

A filter also cuts the rows a search reads inside the log database, which is the bound a broad search reaches first. For that bound, refer to [Limits](/en/documentation/platform/real-time-events/limits/).

---

## Prerequisites

- An Azion account. To create one, refer to [How to create an account on Azion](/en/documentation/fundamentals/creating-account/).
- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- A data source that holds records over the period you want to search.
- The variables you want to match. To read what one record carries, refer to [Read an event record](/en/documentation/guides/platform/observability/understand-logs/).

---

## Apply a filter

**Filter by** reads SQL, and a search must be in one of the two formats this page describes. A search with a blank **Filter by** field returns every record the selected data source holds inside the selected period.

To filter a search in Azion Console:

1. **Open Real-Time Events**

   Access [Azion Console](https://console.azion.com) > **Products menu** > **Observe** > **Real-Time Events**.

2. **Select the data source**

   In **Data Sources**, select the product whose records you want to read.

3. **Set the period**

   In **Time Filter**, select the period the search covers.

4. **Enter the filter**

   In **Filter by**, enter an expression. For example:

   ```text
   status='404'
   ```

5. **Select Refresh**

The result holds only the records that match the expression.

> **Note**
>
> The `timestamp` variable cannot be used as a key in a search, because **Time Filter** sets the period the search covers.

---

## Match an exact value

The first format returns the records whose variable holds exactly the value passed:

```text
key='value'
```

- `key`: one of the variables of the data source the search reads.
- `=`: the search matches the value passed exactly.
- `value`: a value in string or integer format.

---

## Match part of a value

The second format returns the records whose variable holds a value similar to the one passed:

```text
key like '%value%'
```

- `key`: one of the variables of the data source the search reads.
- `like`: the search matches a value similar to the one passed.
- `%value%`: a value in string or integer format, surrounded by the `%` character.

The `%value%` item takes three forms, and the position of `%` decides what the search matches:

- `%value%`: matches the values that contain the entire specified value.
- `%value`: matches the values that end with the specified value.
- `value%`: matches the values that begin with the specified value.

---

## Combine conditions

`AND`, `OR`, and `NOT` combine conditions in one search, so a filter can carry more than one variable. For example, `status='200' AND scheme='https'` returns the records that match both conditions.

---

## Example filters

Each row names a variable with its leading `$`, and the search that matches it. The key in the search is the variable name without the `$`.

| Variable               | SQL query                          |
| ---------------------- | ---------------------------------- |
| `$status`              | `status='404'`                     |
| `$status` + `$scheme`  | `status='200' AND scheme='https'`  |
| `$endpoint_type`       | `endpoint_type='datadog'`          |
| `$geoloc_country_name` | `geoloc_country_name='Germany'`    |
| `$http_user_agent`     | `http_user_agent like '%Firefox%'` |
| `$http_user_agent`     | `http_user_agent like '%fox%'`     |

The last two rows pass two different strings to the same wildcard form. `%value%` matches every value that contains the string, so `'%fox%'` also returns the records that `'%Firefox%'` returns.

---

## Next steps

- [Read an event record](/en/documentation/guides/platform/observability/understand-logs.md): Open one record and read every variable the event wrote.
- [Data sources](/en/documentation/platform/real-time-events/data-sources.md): Every data source, the variables it carries, and the periods Time Filter offers.
- [Investigate a request with the GraphQL API](/en/documentation/guides/platform/observability/investigate-requests-graphql-api.md): Filter the same event records from a query instead of from Azion Console.
- [Limits](/en/documentation/platform/real-time-events/limits.md): The rows a query reads and returns, and the period a search can ask for.
