Declare your own atoms
Declare your own atoms
Declare the identifiers only your data has, ticket ids and customer numbers here, so each lexes
as one token a pattern names as \{name}; test them, then find, count and mask them. The forms
of a declaration are on pattern files.
$ cat ops.trex
shape ticket = `[A-Z]{2,5}-\d{1,5}`
shape customer = `C\d{5}`
test ticket accepts "OPS-1234" "DB-77" rejects "ops-1234" "OPS1234"
test customer accepts "C00042" rejects "C42"
$ cat ops.log
2026-09-27T09:00:01Z OPS-1234 opened for C00042 by ann
2026-09-27T09:05:12Z DB-77 linked to OPS-1234
2026-09-27T09:07:40Z OPS-1250 opened for C00077 by bob
2026-09-27T09:12:03Z OPS-1234 closed for C00042
Test the declarations
Each test line passes when its accepts texts match whole and its rejects texts match
nowhere:
$ trex lib --test ops.trex
ops.trex: 2 tests passed
Find them
$ trex scan '\{ticket}:t "opened" "for" \{customer}:c' --lib ops.trex ops.log --format '${line}: ${t} for ${c}'
1: OPS-1234 for C00042
3: OPS-1250 for C00077
Import-TrexAtom declares the file for the rest of the session; -Library $ops hands one
cmdlet the atoms instead, so a script reads the same atoms in any session.
Count them
$ trex top '\{ticket}:t' '${t}' --lib ops.trex ops.log
OPS-1234 3
DB-77 1
OPS-1250 1
Mask them
A pseudonym gives each distinct value the same stand-in wherever it occurs, named after the atom, so the masked log still shows which lines are about one customer:
$ trex redact '\{customer}' --mask pseudonym --lib ops.trex ops.log
2026-09-27T09:00:01Z OPS-1234 opened for CUSTOMER_1 by ann
2026-09-27T09:05:12Z DB-77 linked to OPS-1234
2026-09-27T09:07:40Z OPS-1250 opened for CUSTOMER_2 by bob
2026-09-27T09:12:03Z OPS-1234 closed for CUSTOMER_1