Skip to main content

Text match operator (~)

The ~ operator checks whether a specified field matches a free-text pattern. It's the underlying mechanism behind the find / text command, which is a shorthand for combining filter with a ~ text match.

Syntax​

<keypath> ~ '<text>'

Field-specific vs. all-fields matching​

Use ~ when you know which field holds the value you're searching for:

source logs
| filter msg ~ 'eu-west-1a'

This is equivalent to:

source logs
| find 'eu-west-1a' in msg

When you don't know which field contains the value, use the all-fields variant ~~ (also available as the wildfind / wildtext command) instead:

source logs
| filter $d ~~ 'eu-west-1a'

~~ is significantly slower than ~, since it must inspect every root-level field of every document. Prefer ~ whenever the keypath is known.

Combining with other filters​

~ can be combined with additional filter stages, like any other boolean expression:

source logs
| filter msg ~ 'timeout'
| filter $m.severity == 'Error'

~ vs. contains()​

~ performs a text match, not a strict substring check. For case-sensitive substring containment, use contains() instead — see case_contains and case_find for the equivalents inside case expressions.

See also​

Last updated on