Filter events
Narrow a Real-Time Events search with the Filter by field, using the key and value syntax it accepts and the wildcards that widen a match.
You can narrow a Real-Time Events search with the Filter by field in Azion Console, so the result holds only the records that carry the values you name. Filter by is a control of the classic view, which is the view Real-Time Events opens on.
A filter names a variable and a value. The variables a data source carries, and the values each one accepts, therefore decide what a search can match. For both, refer to Data sources.
A filter also cuts the rows a search reads inside the log database, which is the bound a broad search reaches first. For that bound, refer to Limits.
Prerequisites
- An Azion account. To create one, refer to How to create an account on Azion.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
- A data source that holds records over the period you want to search.
- The variables you want to match. To read what one record carries, refer to Read an event record.
Apply a filter
Filter by reads SQL, and a search must be in one of the two formats this page describes. A search with a blank Filter by field returns every record the selected data source holds inside the selected period.
To filter a search in Azion Console:
Access Azion Console > Products menu > Observe > Real-Time Events.
In Data Sources, select the product whose records you want to read.
In Time Filter, select the period the search covers.
In Filter by, enter an expression. For example:
The result holds only the records that match the expression.
Match an exact value
The first format returns the records whose variable holds exactly the value passed:
key: one of the variables of the data source the search reads.=: the search matches the value passed exactly.value: a value in string or integer format.
Match part of a value
The second format returns the records whose variable holds a value similar to the one passed:
key: one of the variables of the data source the search reads.like: the search matches a value similar to the one passed.%value%: a value in string or integer format, surrounded by the%character.
The %value% item takes three forms, and the position of % decides what the search matches:
%value%: matches the values that contain the entire specified value.%value: matches the values that end with the specified value.value%: matches the values that begin with the specified value.
Combine conditions
AND, OR, and NOT combine conditions in one search, so a filter can carry more than one variable. For example, status='200' AND scheme='https' returns the records that match both conditions.
Example filters
Each row names a variable with its leading $, and the search that matches it. The key in the search is the variable name without the $.
| Variable | SQL query |
|---|---|
$status | status='404' |
$status + $scheme | status='200' AND scheme='https' |
$endpoint_type | endpoint_type='datadog' |
$geoloc_country_name | geoloc_country_name='Germany' |
$http_user_agent | http_user_agent like '%Firefox%' |
$http_user_agent | http_user_agent like '%fox%' |
The last two rows pass two different strings to the same wildcard form. %value% matches every value that contains the string, so '%fox%' also returns the records that '%Firefox%' returns.