Skip to content
Declare your own atoms

Declare your own atoms

Declare your own atoms

Declare the identifiers only your data has, ticket ids and customer numbers here, so each lexes as one token a pattern names as \{name}; test them, then find, count and mask them. The forms of a declaration are on pattern files.

$ cat ops.trex
shape ticket = `[A-Z]{2,5}-\d{1,5}`
shape customer = `C\d{5}`
test ticket accepts "OPS-1234" "DB-77" rejects "ops-1234" "OPS1234"
test customer accepts "C00042" rejects "C42"
$ cat ops.log
2026-09-27T09:00:01Z OPS-1234 opened for C00042 by ann
2026-09-27T09:05:12Z DB-77 linked to OPS-1234
2026-09-27T09:07:40Z OPS-1250 opened for C00077 by bob
2026-09-27T09:12:03Z OPS-1234 closed for C00042

Test the declarations

Each test line passes when its accepts texts match whole and its rejects texts match nowhere:

$ trex lib --test ops.trex
ops.trex: 2 tests passed

Find them

$ trex scan '\{ticket}:t "opened" "for" \{customer}:c' --lib ops.trex ops.log --format '${line}: ${t} for ${c}'
1: OPS-1234 for C00042
3: OPS-1250 for C00077

Import-TrexAtom declares the file for the rest of the session; -Library $ops hands one cmdlet the atoms instead, so a script reads the same atoms in any session.

Count them

$ trex top '\{ticket}:t' '${t}' --lib ops.trex ops.log
OPS-1234  3
DB-77     1
OPS-1250  1

Mask them

A pseudonym gives each distinct value the same stand-in wherever it occurs, named after the atom, so the masked log still shows which lines are about one customer:

$ trex redact '\{customer}' --mask pseudonym --lib ops.trex ops.log
2026-09-27T09:00:01Z OPS-1234 opened for CUSTOMER_1 by ann
2026-09-27T09:05:12Z DB-77 linked to OPS-1234
2026-09-27T09:07:40Z OPS-1250 opened for CUSTOMER_2 by bob
2026-09-27T09:12:03Z OPS-1234 closed for CUSTOMER_1