Text match operator (~)
The ~ operator checks whether a specified field matches a free-text pattern. It's the underlying mechanism behind the find / text command, which is a shorthand for combining filter with a ~ text match.
Syntax
<keypath> ~ '<text>'
Field-specific vs. all-fields matching
Use ~ when you know which field holds the value you're searching for:
source logs
| filter msg ~ 'eu-west-1a'
This is equivalent to:
source logs
| find 'eu-west-1a' in msg
When you don't know which field contains the value, use the all-fields variant ~~ (also available as the wildfind / wildtext command) instead:
source logs
| filter $d ~~ 'eu-west-1a'
~~ is significantly slower than ~, since it must inspect every root-level field of every document. Prefer ~ whenever the keypath is known.
Combining with other filters
~ can be combined with additional filter stages, like any other boolean expression:
source logs
| filter msg ~ 'timeout'
| filter $m.severity == 'Error'
~ vs. contains()
~ performs a text match, not a strict substring check. For case-sensitive substring containment, use contains() instead — see case_contains and case_find for the equivalents inside case expressions.