Skip to content
Query records

Query the records of a log

Query the records of a log

Keep the entries of a log that hold, or lack, the patterns you name, where an entry runs over several lines. The units and quantifiers are on records.

$ cat events.log
2026-09-15T10:00:00Z login ok
  user bob@x.com from 10.0.0.1
2026-09-15T10:01:00Z login failed
  user amy@y.org from 10.0.0.2
2026-09-15T10:02:00Z logout
  user bob@x.com

Entries that lack a pattern

A timestamp at the start of a line begins an entry, so ^ \T makes each entry one record. Keep the entries holding no address:

$ trex scan --none -e '\I' --record-start '^ \T' events.log
2026-09-15T10:02:00Z logout
  user bob@x.com

Entries that hold every pattern

--all keeps an entry holding each pattern; a pattern may carry a typed predicate, here an address inside one network:

$ trex scan --all -e '\E' -e '\I{in:10.0.0.0/24}' --record-start '^ \T' events.log
2026-09-15T10:00:00Z login ok
  user bob@x.com from 10.0.0.1
2026-09-15T10:01:00Z login failed
  user amy@y.org from 10.0.0.2

--any keeps an entry holding one of the patterns, --at-least N one holding N of them, and --not PATTERN drops an entry holding that pattern under any of them. --count counts the entries kept, and --record paragraph, --record unit:assign and the other units cut the records another way.