Query the records of a log
Query the records of a log
Keep the entries of a log that hold, or lack, the patterns you name, where an entry runs over several lines. The units and quantifiers are on records.
$ cat events.log
2026-09-15T10:00:00Z login ok
user bob@x.com from 10.0.0.1
2026-09-15T10:01:00Z login failed
user amy@y.org from 10.0.0.2
2026-09-15T10:02:00Z logout
user bob@x.com
Entries that lack a pattern
A timestamp at the start of a line begins an entry, so ^ \T makes each entry one record. Keep
the entries holding no address:
$ trex scan --none -e '\I' --record-start '^ \T' events.log
2026-09-15T10:02:00Z logout
user bob@x.com
Entries that hold every pattern
--all keeps an entry holding each pattern; a pattern may carry a typed predicate, here an
address inside one network:
$ trex scan --all -e '\E' -e '\I{in:10.0.0.0/24}' --record-start '^ \T' events.log
2026-09-15T10:00:00Z login ok
user bob@x.com from 10.0.0.1
2026-09-15T10:01:00Z login failed
user amy@y.org from 10.0.0.2
--any keeps an entry holding one of the patterns, --at-least N one holding N of them, and
--not PATTERN drops an entry holding that pattern under any of them. --count counts the
entries kept, and --record paragraph, --record unit:assign and the other units cut the
records another way.