§³§Ó§Ö §æ§å§ß§Ü§è§Ú?§Ö §ß§Ñ§Ó§Ö§Õ§Ö§ß§Ö §à§Ó§Õ§Ö §ã§å §á§à§Õ§â§Ø§Ñ§ß§Ö §å:
§¶§å§ß§Ü§è§Ú?§Ö §ã§å §ß§Ñ§Ó§Ö§Õ§Ö§ß§Ö §Ò§Ö§Ù §Õ§à§Õ§Ñ§ä§ß§Ú§ç §Ú§ß§æ§à§â§Þ§Ñ§è§Ú?§Ñ. §¬§Ý§Ú§Ü§ß§Ú§ä§Ö §ß§Ñ §æ§å§ß§Ü§è§Ú?§å §Õ§Ñ §Ò§Ú§ã§ä§Ö §Ó§Ú§Õ§Ö§Ý§Ú §ã§Ó§Ö §Õ§Ö§ä§Ñ?§Ö.
Function | Description |
---|---|
change | §ª§Ù§ß§à§ã §â§Ñ§Ù§Ý§Ú§Ü§Ö §Ú§Ù§Þ§Ö?§å §á§â§Ö§ä§ç§à§Õ§ß§Ö §Ú §ß§Ñ?§ß§à§Ó§Ú?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú. |
changecount | §¢§â§à? §á§â§à§Þ§Ö§ß§Ñ §Ú§Ù§Þ§Ö?§å §ã§å§ã§Ö§Õ§ß§Ú§ç §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å§ß§å§ä§Ñ§â §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö. |
count | §¢§â§à? §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å§ß§å§ä§Ñ§â §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö. |
countunique | §¢§â§à? ?§Ö§Õ§Ú§ß§ã§ä§Ó§Ö§ß§Ú§ç §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å§ß§å§ä§Ñ§â §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö. |
find | §±§â§à§ß§Ñ§Ý§Ñ§Ø§Ö?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä §Ü§à?§Ñ §ã§Ö §á§à§Õ§å§Õ§Ñ§â§Ñ §å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Þ §á§Ö§â§Ú§à§Õ§å §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö. |
first | §±§â§Ó§Ñ (§ß§Ñ?§ã§ä§Ñ§â§Ú?§Ñ) §Ó§â§Ö§Õ§ß§à§ã§ä §å§ß§å§ä§Ñ§â §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö. |
fuzzytime | §±§â§à§Ó§Ö§â§Ñ §Ü§à§Ý§Ú§Ü§à §ã§Ö §Ó§â§Ö§Þ§Ö §á§Ñ§ã§Ú§Ó§ß§à§Ô §Ñ§Ô§Ö§ß§ä§Ñ §â§Ñ§Ù§Ý§Ú§Ü§å?§Ö §à§Õ §Ó§â§Ö§Þ§Ö§ß§Ñ Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ/§á§â§à§Ü§ã§Ú?§Ñ. |
last | §¯§Ñ?§ß§à§Ó§Ú?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä. |
logeventid | §±§â§à§Ó§Ö§â§Ñ §Õ§Ñ §Ý§Ú §ã§Ö ID §Õ§à§Ô§Ñ?§Ñ?§Ñ §á§à§ã§Ý§Ö§Õ?§Ö§Ô §å§ß§à§ã§Ñ §å §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ú §á§à§Õ§å§Õ§Ñ§â§Ñ §ã§Ñ §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§Þ §Ú§Ù§â§Ñ§Ù§à§Þ. |
logseverity | §°§Ù§Ò§Ú?§ß§à§ã§ä §á§à§ã§Ý§Ö§Õ?§Ö§Ô §å§ß§à§ã§Ñ §å §Õ§ß§Ö§Ó§ß§Ú§Ü. |
logsource | §±§â§à§Ó§Ö§â§Ñ §Õ§Ñ §Ý§Ú §Ú§Ù§Ó§à§â §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ö §á§à§ã§Ý§Ö§Õ?§Ö§Ô §å§ß§à§ã§Ñ §å §Õ§ß§Ö§Ó§ß§Ú§Ü §à§Õ§Ô§à§Ó§Ñ§â§Ñ §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Þ §Ú§Ù§â§Ñ§Ù§å. |
monodec | §±§â§à§Ó§Ö§â§Ú§ä§Ö §Õ§Ñ §Ý§Ú ?§Ö §Õ§à§ê§Ý§à §Õ§à §Þ§à§ß§à§ä§à§ß§à§Ô §ã§Þ§Ñ?§Ö?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú. |
monoinc | §±§â§à§Ó§Ö§â§Ú§ä§Ö §Õ§Ñ §Ý§Ú ?§Ö §Õ§à§ê§Ý§à §Õ§à §Þ§à§ß§à§ä§à§ß§à§Ô §á§à§Ó§Ö?§Ñ?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú. |
nodata | §±§â§à§Ó§Ö§â§Ú §Õ§Ñ §Ý§Ú §ß§Ö§Þ§Ñ §á§â§Ú§Þ?§Ö§ß§Ú§ç §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ. |
percentile | P-§ä§Ú §á§Ö§â§è§Ö§ß§ä§Ú§Ý §á§Ö§â§Ú§à§Õ§Ñ, §Ô§Õ§Ö ?§Ö P (§á§â§à§è§Ö§ß§Ñ§ä) §à§Õ§â§Ö?§Ö§ß §ä§â§Ö?§Ú§Þ §á§Ñ§â§Ñ§Þ§Ö§ä§â§à§Þ. |
rate | §±§â§à§ã§Ö§é§ß§Ñ §ã§ä§à§á§Ñ §á§à §ã§Ö§Ü§å§ß§Õ§Ú §á§à§Ó§Ö?§Ñ?§Ñ §å §Þ§à§ß§à§ä§à§ß§à §â§Ñ§ã§ä§å?§Ö§Þ §Ò§â§à?§Ñ§é§å §å §à§Ü§Ó§Ú§â§å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §Ó§â§Ö§Þ§Ö§ß§ã§Ü§à§Ô §á§Ö§â§Ú§à§Õ§Ñ. |
/host/key
?§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ú §à§Ò§Ñ§Ó§Ö§Ù§ß§Ú §á§â§Ó§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â §Ù§Ñ §æ§å§ß§Ü§è§Ú?§Ö §Ü§à?§Ö §ã§Ö §â§Ö§æ§Ö§â§Ö§ß§è§Ú§â§Ñ?§å §ß§Ñ §Ú§ã§ä§à§â§Ú?§å §ã§ä§Ñ§Ó§Ü§Ö §Õ§à§Þ§Ñ?§Ú§ß§Ñ(sec|#num)<:time shift>
?§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ú §Õ§â§å§Ô§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â §Ù§Ñ §æ§å§ß§Ü§è§Ú?§Ö §Ü§à?§Ö §å§á§å?§å?§å §ß§Ñ §Ú§ã§ä§à§â§Ú?§å §ã§ä§Ñ§Ó§Ü§Ö §Õ§à§Þ§Ñ?§Ú§ß§Ñ, §Ô§Õ§Ö ?§Ö: - sec - §Þ§Ñ§Ü§ã§Ú§Þ§å§Þ §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö §å §ã§Ö§Ü§å§ß§Õ§Ñ§Þ§Ñ (§Þ§à§Ô§å §ã§Ö §Ü§à§â§Ú§ã§ä§Ú§ä§Ú §Ó§â§Ö§Þ§Ö §ã§å§æ§Ú§Ü§ã§Ú) §Ú§Ý§Ú - #num - §Þ§Ñ§Ü§ã§Ú§Þ§å§Þ §à§á§ã§Ö§Ô §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö §å §ß§Ñ?§ß§à§Ó§Ú?§Ö§Þ §á§â§Ú§Ü§å§á?§Ñ?§å §Ó§â§Ö§Õ§ß§à§ã§ä§Ú (§Ñ§Ü§à §Ú§Þ §á§â§Ö§ä§ç§à§Õ§Ú §ç§Ö§ê §à§Ù§ß§Ñ§Ü§Ñ) - time shift (§à§á§è§Ú§à§ß§à) §à§Þ§à§Ô§å?§Ñ§Ó§Ñ §á§à§Þ§Ö§â§Ñ?§Ö §ä§Ñ§é§Ü§Ö §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö §ß§Ñ§Ù§Ñ§Õ §å §Ó§â§Ö§Þ§Ö. §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ó§Ú§ê§Ö §Õ§Ö§ä§Ñ?§Ñ §Ù§Ñ §ß§Ñ§Ó§à?§Ö?§Ö §Ó§â§Ö§Þ§Ö§ß§ã§Ü§à§Ô §á§à§Þ§Ö§â§Ñ?§Ñ.§¯§Ö§Ü§Ö §à§á§ê§ä§Ö §ß§Ñ§á§à§Þ§Ö§ß§Ö §à §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú§Þ§Ñ §æ§å§ß§Ü§è§Ú?§Ö:
<
>
/host/key
§Ú (sec|#num)<:time shift>
§á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú §ß§Ú§Ü§Ñ§Õ§Ñ §ß§Ö §ã§Þ§Ö?§å §Ò§Ú§ä§Ú §á§à§Õ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ§ª§Ù§ß§à§ã §â§Ñ§Ù§Ý§Ú§Ü§Ö §Ú§Ù§Þ§Ö?§å §á§â§Ö§ä§ç§à§Õ§ß§Ö §Ú §ß§Ñ?§ß§à§Ó§Ú?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.
§©§Ñ §ã§ä§â§Ú§ß§Ô§à§Ó§Ö §Ó§â§Ñ?§Ñ: 0 - §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §ã§å ?§Ö§Õ§ß§Ñ§Ü§Ö; 1 - §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §ã§Ö §â§Ñ§Ù§Ý§Ú§Ü§å?§å.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú: §á§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú.
§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:
+4
-2
-2.5
§±§â§Ú§Þ§Ö§â§Ú:
§¢§â§à? §á§â§à§Þ§Ö§ß§Ñ §Ú§Ù§Þ§Ö?§å §ã§å§ã§Ö§Õ§ß§Ú§ç §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å §à§Ü§Ó§Ú§â§å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
§©§Ñ §ß§Ö§ß§å§Þ§Ö§â§Ú§é§Ü§Ö §ä§Ú§á§à§Ó§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú, §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â mode §ã§Ö §Ù§Ñ§ß§Ö§Þ§Ñ§â§å?§Ö.
§±§â§Ú§Þ§Ö§â§Ú:
changecount(/host/key,1w) #the number of value changes for the last week until now
changecount(/host/key,#10,"inc") #the number of value increases (relative to the adjacent value) among the last 10 values
changecount(/host/key,24h,"dec") #the number of value decreases (relative to the adjacent value) for the last 24 hours until now
§¢§â§à? §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å§ß§å§ä§Ñ§â §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
operators
:pattern
§à§ã§Ö§ä?§Ú§Ó§à §ß§Ñ §Þ§Ñ§Ý§Ñ §Ú §Ó§Ö§Ý§Ú§Ü§Ñ §ã§Ý§à§Ó§Ñpattern
§ß§Ö§à§ã§Ö§ä?§Ú§Ó§à §ß§Ñ §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:
pattern
§ã§Ö §Þ§à§Ø§Ö §ß§Ñ§Ó§Ö§ã§ä§Ú §Ü§Ñ§à §Õ§Ó§Ñ §Ò§â§à?§Ñ, §â§Ñ§Ù§Õ§Ó§à?§Ö§ß§Ñ §ã§Ñ '/': number_to_compare_with/mask. count() §Ú§Ù§â§Ñ§é§å§ß§Ñ§Ó§Ñ "§Ò§Ú§ä§à§Ó§ã§Ü§à AND" §Ú§Ù §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §Ú §Þ§Ñ§ã§Ü§Ö §Ú §å§á§à§â§Ö?§å?§Ö §â§Ö§Ù§å§Ý§ä§Ñ§ä §ã§Ñ §Ò§â§à?³å§Ù§Ñ³å§å§á§à§â§Ö?§Ú§Ó§Ñ?§Ö³å§ã§Ñ. §¡§Ü§à ?§Ö §â§Ö§Ù§å§Ý§ä§Ñ§ä "§Ò§Ú§ä§à§Ó§ã§Ü§à AND" ?§Ö§Õ§ß§Ñ§Ü number_to_compare_with, §Ó§â§Ö§Õ§ß§à§ã§ä §ã§Ö §â§Ñ§é§å§ß§Ñ.pattern
§Þ§à§Ø§Ö §Ò§Ú§ä§Ú §à§Ò§Ú§é§Ñ§ß §Ú§Ý§Ú §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú (§Ü§à?§Ú §á§à§é§Ú?§Ö §ã§Ñ '@') §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú §Ú§Ù§â§Ñ§Ù. §µ §ã§Ý§å§é§Ñ?§å §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú§ç §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§ç §Ú§Ù§â§Ñ§Ù§Ñ, §à§ã§Ö§ä?§Ú§Ó§à§ã§ä §ß§Ñ §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ §ã§Ö §ß§Ñ§ã§Ý§Ö?§å?§Ö §Ú§Ù §á§à§Õ§Ö§ê§Ñ§Ó§Ñ?§Ñ §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú§ç §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§ç §Ú§Ù§â§Ñ§Ù§Ñ. §©§Ñ §á§à§ä§â§Ö§Ò§Ö §á§à§Õ§å§Õ§Ñ§â§Ñ?§Ñ §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ, §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §ã§Ñ §á§à§Ü§â§Ö§ä§ß§Ú§Þ §Ò§â§à?§Ö§Þ §å§Ó§Ö§Ü ?§Ö §Ò§Ú§ä§Ú §á§â§Ö§Õ§ã§ä§Ñ§Ó?§Ö§ß§Ö §ã§Ñ 4 §Õ§Ö§è§Ú§Þ§Ñ§Ý§ß§Ö §è§Ú§æ§â§Ö §á§à§ã§Ý§Ö '.'. §´§Ñ§Ü§à?§Ö §Ú§Þ§Ñ?§ä§Ö §ß§Ñ §å§Þ§å §Õ§Ñ §Ù§Ñ §Ó§Ö§Ý§Ú§Ü§Ö §Ò§â§à?§Ö§Ó§Ö §â§Ñ§Ù§Ý§Ú§Ü§Ñ §å §Õ§Ö§è§Ú§Þ§Ñ§Ý§ß§à? (§é§å§Ó§Ñ§ß§à? §å §Ò§Ñ§Ù§Ú §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ) §Ú §Ò§Ú§ß§Ñ§â§ß§à? (§Ü§à?§å §Ü§à§â§Ú§ã§ä§Ú Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â) §Þ§à§Ø§Ö §å§ä§Ú§è§Ñ§ä§Ú §ß§Ñ 4. §Õ§Ö§è§Ú§Þ§Ñ§Ý§å.§±§â§Ú§Þ§Ö§â§Ú:
count(/host/key,10m) #the values for the last 10 minutes until now
count(/host/key,10m,"like","error") #the number of values for the last 10 minutes until now that contain 'error'
count(/host/key,10m,,12) #the number of values for the last 10 minutes until now that equal '12'
count(/host/key,10m,"gt",12) #the number of values for the last 10 minutes until now that are over '12'
count(/host/key,#10,"gt",12) #the number of values within the last 10 values until now that are over '12'
count(/host/key,10m:now-1d,"gt",12) #the number of values between 24 hours and 10 minutes and 24 hours ago from now that were over '12'
count(/host/key,10m,"bitand","6/7") #the number of values for the last 10 minutes until now having '110' (in binary) in the 3 least significant bits
count(/host/key,10m:now-1d) #the number of values between 24 hours and 10 minutes and 24 hours ago from now
§¢§â§à? ?§Ö§Õ§Ú§ß§ã§ä§Ó§Ö§ß§Ú§ç §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Þ §á§Ö§â§Ú§à§Õ§å §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
operators
:§å§Ù§à§â§è§å
pattern
§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:
pattern
§ã§Ö §Þ§à§Ø§Ö §ß§Ñ§Ó§Ö§ã§ä§Ú §Ü§Ñ§à §Õ§Ó§Ñ §Ò§â§à?§Ñ, §â§Ñ§Ù§Õ§Ó§à?§Ö§ß§Ñ §ã§Ñ '/': number_to_compare_with/mask. countunique() §Ú§Ù§â§Ñ§é§å§ß§Ñ§Ó§Ñ "§Ò§Ú§ä§à§Ó§ã§Ü§à AND" §Ú§Ù §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §Ú §Þ§Ñ§ã§Ü§Ö §Ú §å§á§à§â§Ö?§å?§Ö §â§Ö§Ù§å§Ý§ä§Ñ§ä §ã§Ñ number_to_compare_with. §¡§Ü§à ?§Ö §â§Ö§Ù§å§Ý§ä§Ñ§ä "§Ò§Ú§ä§à§Ó§ã§Ü§à AND" ?§Ö§Õ§ß§Ñ§Ü number_to_compare_with, §Ó§â§Ö§Õ§ß§à§ã§ä §ã§Ö §â§Ñ§é§å§ß§Ñ.pattern
§Þ§à§Ø§Ö §Ò§Ú§ä§Ú §à§Ò§Ú§é§Ñ§ß §Ú§Ý§Ú §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú (§Ü§à?§Ú §á§à§é§Ú?§Ö §ã§Ñ '@') §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú §Ú§Ù§â§Ñ§Ù. §µ §ã§Ý§å§é§Ñ?§å §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú§ç §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§ç §Ú§Ù§â§Ñ§Ù§Ñ, §à§ã§Ö§ä?§Ú§Ó§à§ã§ä §ß§Ñ §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ §ã§Ö §ß§Ñ§ã§Ý§Ö?§å?§Ö §Ú§Ù §á§à§Õ§Ö§ê§Ñ§Ó§Ñ?§Ñ §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú§ç §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§ç §Ú§Ù§â§Ñ§Ù§Ñ. §©§Ñ §á§à§ä§â§Ö§Ò§Ö §á§à§Õ§å§Õ§Ñ§â§Ñ?§Ñ §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ, §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §ã§Ñ §á§Ý§å§ä§Ñ?§å?§Ú§Þ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú§Þ§Ñ ?§Ö §å§Ó§Ö§Ü §Ò§Ú§ä§Ú §á§â§Ö§Õ§ã§ä§Ñ§Ó?§Ö§ß§Ö §ã§Ñ 4 §Õ§Ö§è§Ú§Þ§Ñ§Ý§ß§Ö §è§Ú§æ§â§Ö §á§à§ã§Ý§Ö '.'. §´§Ñ§Ü§à?§Ö §Ú§Þ§Ñ?§ä§Ö §ß§Ñ §å§Þ§å §Õ§Ñ §Ù§Ñ §Ó§Ö§Ý§Ú§Ü§Ö §Ò§â§à?§Ö§Ó§Ö §â§Ñ§Ù§Ý§Ú§Ü§Ñ §å §Õ§Ö§è§Ú§Þ§Ñ§Ý§ß§à? (§é§å§Ó§Ñ§ß§à? §å §Ò§Ñ§Ù§Ú §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ) §Ú §Ò§Ú§ß§Ñ§â§ß§à? (§Ü§à?§å §Ü§à§â§Ú§ã§ä§Ú Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â) §Þ§à§Ø§Ö §å§ä§Ú§è§Ñ§ä§Ú §ß§Ñ 4. §Õ§Ö§è§Ú§Þ§Ñ§Ý§å.§±§â§Ú§Þ§Ö§â§Ú:
countunique(/host/key,10m) #the number of unique values for the last 10 minutes until now
countunique(/host/key,10m,"like","error") #the number of unique values for the last 10 minutes until now that contain 'error'
countunique(/host/key,10m,,12) #the number of unique values for the last 10 minutes until now that equal '12'
countunique(/host/key,10m,"gt",12) #the number of unique values for the last 10 minutes until now that are over '12'
countunique(/host/key,#10,"gt",12) #the number of unique values within the last 10 values until now that are over '12'
countunique(/host/key,10m:now-1d,"gt",12) #the number of unique values between 24 hours and 10 minutes and 24 hours ago from now that were over '12'
countunique(/host/key,10m,"bitand","6/7") #the number of unique values for the last 10 minutes until now having '110' (in binary) in the 3 least significant bits
countunique(/host/key,10m:now-1d) #the number of unique values between 24 hours and 10 minutes and 24 hours ago from now
§±§â§à§ß§Ñ?§Ú§ä§Ö §á§à§Õ§å§Õ§Ñ§â§Ñ?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Þ §á§Ö§â§Ú§à§Õ§å §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.
§£§â§Ñ?§Ñ: 1 - §á§â§à§ß§Ñ?§Ö§ß§à; 0 - §Ú§ß§Ñ§é§Ö.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
operators
:pattern
(§à§ã§Ö§ä?§Ú§Ó§à §ß§Ñ §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ)pattern
pattern
operator
regexp, iregexp.§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:
pattern
§Þ§à§Ø§Ö §Ò§Ú§ä§Ú §à§Ò§Ú§é§Ñ§ß §Ú§Ý§Ú §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú (§Ü§à?§Ú §á§à§é§Ú?§Ö §ã§Ñ '@') §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú §Ú§Ù§â§Ñ§Ù. §µ §ã§Ý§å§é§Ñ?§å §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú§ç §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§ç §Ú§Ù§â§Ñ§Ù§Ñ, §à§ã§Ö§ä?§Ú§Ó§à§ã§ä §ß§Ñ §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ §ã§Ö §ß§Ñ§ã§Ý§Ö?§å?§Ö §Ú§Ù §á§à§Õ§Ö§ê§Ñ§Ó§Ñ?§Ñ §Ô§Ý§à§Ò§Ñ§Ý§ß§à§Ô §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ.§±§â§Ú§Þ§Ö§â:
find(/host/key,10m,"like","error") #find a value that contains 'error' within the last 10 minutes until now
§±§â§Ó§Ñ (§ß§Ñ?§ã§ä§Ñ§â§Ú?§Ñ) §Ó§â§Ö§Õ§ß§à§ã§ä §å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Þ §á§Ö§â§Ú§à§Õ§å §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
§´§Ñ§Ü§à?§Ö §á§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö last().
§±§â§Ú§Þ§Ö§â:
§±§â§à§Ó§Ö§â§Ú§ä§Ö §Ü§à§Ý§Ú§Ü§à §ã§Ö §Ó§â§Ö§Þ§Ö §á§Ñ§ã§Ú§Ó§ß§à§Ô §Ñ§Ô§Ö§ß§ä§Ñ §â§Ñ§Ù§Ý§Ú§Ü§å?§Ö §à§Õ §Ó§â§Ö§Þ§Ö§ß§Ñ Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ/§á§â§à§Ü§ã§Ú?§Ñ.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer.
§£§â§Ñ?§Ñ: 1 - §â§Ñ§Ù§Ý§Ú§Ü§Ñ §Ú§Ù§Þ§Ö?§å §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §á§Ñ§ã§Ú§Ó§ß§Ö §ã§ä§Ñ§Ó§Ü§Ö (§Ü§Ñ§à §Ó§â§Ö§Þ§Ö§ß§ã§Ü§Ö §à§Ù§ß§Ñ§Ü§Ö) §Ú §Ó§â§Ö§Þ§Ö§ß§ã§Ü§Ö §à§Ù§ß§Ñ§Ü§Ö Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ/§á§â§à§Ü§ã§Ú?§Ñ (§ã§Ñ§ä §á§â§Ú§Ü§å§á?§Ñ?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú) ?§Ö §Þ§Ñ?§Ñ §Ú§Ý§Ú ?§Ö§Õ§ß§Ñ§Ü§Ñ §à§Õ sec §ã§Ö§Ü§å§ß§Õ§Ú; 0 - §Ú§ß§Ñ§é§Ö.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:
vfs.file.time[/path/file,modify]
§Õ§Ñ §ã§Ö §á§â§à§Ó§Ö§â§Ú §Õ§Ñ §Ý§Ú §Õ§Ñ§ä§à§ä§Ö§Ü§Ñ §ß§Ú?§Ö §Õ§à§Ò§Ú?§Ñ§Ý§Ñ §Ñ§Ø§å§â§Ú§â§Ñ?§Ñ §Õ§å§Ø§Ö §Ó§â§Ö§Þ§Ö;fuzzytime(/Host/system.localtime,60s)=0 or last(/Host/trap)<>0
.§±§â§Ú§Þ§Ö§â:
fuzzytime(/host/key,60s)=0 #§à§ä§Ü§â§Ú§Ó§Ñ §á§â§à§Ò§Ý§Ö§Þ §Ñ§Ü§à ?§Ö §Ó§â§Ö§Þ§Ö§ß§ã§Ü§Ñ §â§Ñ§Ù§Ý§Ú§Ü§Ñ §Ó§Ö?§Ñ §à§Õ 60 §ã§Ö§Ü§å§ß§Õ§Ú
§¯§Ñ?§ß§à§Ó§Ú?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:
last(/host/key)
?§Ö §å§Ó§Ö§Ü ?§Ö§Õ§ß§Ñ§Ü§à last(/host/key,#1)
; last(/host/key,#3)
- §ä§â§Ö?§Ñ §ß§Ñ?§ß§à§Ó§Ú?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä (not §ä§â§Ú §á§à§ã§Ý§Ö§Õ?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú);§±§â§Ú§Þ§Ö§â:
last(/host/key) #retrieve the last value
last(/host/key,#2) #retrieve the previous value
last(/host/key,#1) <> last(/host/key,#2) #the last and previous values differ
§±§â§à§Ó§Ö§â§Ú§ä§Ö §Õ§Ñ §Ý§Ú §ã§Ö ID §Õ§à§Ô§Ñ?§Ñ?§Ñ §á§à§ã§Ý§Ö§Õ?§Ö§Ô §å§ß§à§ã§Ñ §å §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ú §á§à§Õ§å§Õ§Ñ§â§Ñ §ã§Ñ §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§Þ §Ú§Ù§â§Ñ§Ù§à§Þ.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Log.
§£§â§Ñ?§Ñ: 0 - §ß§Ö §à§Õ§Ô§à§Ó§Ñ§â§Ñ; 1 - §à§Õ§Ô§à§Ó§Ñ§â§Ñ.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
§°§Ù§Ò§Ú?§ß§à§ã§ä §Õ§ß§Ö§Ó§ß§Ú§Ü§Ñ §á§à§ã§Ý§Ö§Õ?§Ö§Ô §å§ß§à§ã§Ñ §å §Õ§ß§Ö§Ó§ß§Ú§Ü.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Log.
§£§â§Ñ?§Ñ: 0 - §á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§Ñ §à§Ù§Ò§Ú?§ß§à§ã§ä; N - §à§Ù§Ò§Ú?§ß§à§ã§ä (§è§Ö§à §Ò§â§à?, §Ü§à§â§Ú§ã§ß§à §Ù§Ñ Windows §Õ§à§Ô§Ñ?§Ñ?§Ö: 1 - §ª§ß§æ§à§â§Þ§Ñ§è§Ú?§Ö, 2 - §µ§á§à§Ù§à§â§Ö?§Ö, 4 - §¤§â§Ö§ê§Ü§Ñ, 7 - §¯§Ö§å§ã§á§Ö§Ý§Ñ §á§â§à§Ó§Ö§â§Ñ, 8 - §µ§ã§á§Ö§ê§ß§Ñ §á§â§à§Ó§Ö§â§Ñ, 9 - §¬§â§Ú§ä§Ú§é§ß§Ñ, 10 - §¥§Ö§ä§Ñ?§ß§à).
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
§©§Ñ§Ò§Ò§Ú§Ü §á§â§Ö§å§Ù§Ú§Þ§Ñ §à§Ù§Ò§Ú?§ß§à§ã§ä §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ö §Ú§Ù §á§à?§Ñ §ª§ß§æ§à§â§Þ§Ñ§è§Ú?§Ö Windows §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ.
§±§â§à§Ó§Ö§â§Ñ§Ó§Ñ §Õ§Ñ §Ý§Ú §Ú§Ù§Ó§à§â §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ö §á§à§ã§Ý§Ö§Õ?§Ö§Ô §å§ß§à§ã§Ñ §Õ§ß§Ö§Ó§ß§Ú§Ü§Ñ §à§Õ§Ô§à§Ó§Ñ§â§Ñ §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Þ §Ú§Ù§â§Ñ§Ù§å.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: * Log*.
§£§â§Ñ?§Ñ: 0 - §ß§Ö §à§Õ§Ô§à§Ó§Ñ§â§Ñ; 1 - §à§Õ§Ô§à§Ó§Ñ§â§Ñ.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
§°§Ò§Ú§é§ß§à §ã§Ö §Ü§à§â§Ú§ã§ä§Ú §Ù§Ñ Windows §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ.
§±§â§Ú§Þ§Ö§â:
§±§â§à§Ó§Ö§â§Ú§ä§Ö §Õ§Ñ §Ý§Ú ?§Ö §Õ§à§ê§Ý§à §Õ§à §Þ§à§ß§à§ä§à§ß§à§Ô §á§Ñ§Õ§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Integer.
§£§â§Ñ?§Ñ: 1 - §Ñ§Ü§à §ã§Ö §ã§Ó§Ú §Ö§Ý§Ö§Þ§Ö§ß§ä§Ú §å §Ó§â§Ö§Þ§Ö§ß§ã§Ü§à§Þ §á§Ö§â§Ú§à§Õ§å §Ü§à§ß§ä§Ú§ß§å§Ú§â§Ñ§ß§à §ã§Þ§Ñ?§å?§å; 0 - §Ú§ß§Ñ§é§Ö.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
§±§â§Ú§Þ§Ö§â:
monodec(/Host1/system.swap.size[all,free],60s) + monodec(/Host2/system.swap.size[all,free],60s) + monodec(/Host3/system.swap.size[all,free],60s) #calculate in how many hosts there has been a decrease in free swap size
§±§â§à§Ó§Ö§â§Ú§ä§Ö §Õ§Ñ §Ý§Ú ?§Ö §Õ§à§ê§Ý§à §Õ§à §Þ§à§ß§à§ä§à§ß§à§Ô §á§à§Ó§Ö?§Ñ?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: * Integer*.
§£§â§Ñ?§Ñ: 1 - §Ñ§Ü§à §ã§Ö §ã§Ó§Ú §Ö§Ý§Ö§Þ§Ö§ß§ä§Ú §å §Ó§â§Ö§Þ§Ö§ß§ã§Ü§à§Þ §á§Ö§â§Ú§à§Õ§å §Ü§à§ß§ä§Ú§ß§å§Ú§â§Ñ§ß§à §á§à§Ó§Ö?§Ñ§Ó§Ñ?§å; 0 - §Ú§ß§Ñ§é§Ö.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
§±§â§Ú§Þ§Ö§â:
monoinc(/Host1/system.localtime,#3,"strict")=0 #check if the system local time has been increasing consistently
§±§â§à§Ó§Ö§â§Ú§ä§Ö §Õ§Ñ §ß§Ö§Þ§Ñ §á§â§Ú§Þ?§Ö§ß§Ú§ç §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Integer, Float, Character, Text, Log.
§£§â§Ñ?§Ñ: 1 - §Ñ§Ü§à §ß§Ú§ã§å §á§â§Ú§Þ?§Ö§ß§Ú §á§à§Õ§Ñ§è§Ú §ä§à§Ü§à§Þ §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §Ó§â§Ö§Þ§Ö§ß§ã§Ü§à§Ô §á§Ö§â§Ú§à§Õ§Ñ; 0 - §Ú§ß§Ñ§é§Ö.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
nodata(/host/key,0)
?§Ö §ß§Ö§Õ§à§Ù§Ó§à?§Ö§ß§à.§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:
nodata(/host/key,5m,"strict")
; §å §à§Ó§à§Þ §ã§Ý§å§é§Ñ?§å §æ§å§ß§Ü§è§Ú?§Ñ ?§Ö §ã§Ö §á§à§Ü§â§Ö§ß§å§ä§Ú §é§Ú§Þ §á§â§à?§Ö §á§Ö§â§Ú§à§Õ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö (§á§Ö§ä §Þ§Ú§ß§å§ä§Ñ) §Ò§Ö§Ù §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ.P-§ä§Ú §á§Ö§â§è§Ö§ß§ä§Ú§Ý §á§Ö§â§Ú§à§Õ§Ñ, §Ô§Õ§Ö ?§Ö P (§á§â§à§è§Ö§ß§Ñ§ä) §à§Õ§â§Ö?§Ö§ß §ä§â§Ö?§Ú§Þ §á§Ñ§â§Ñ§Þ§Ö§ä§â§à§Þ.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
§±§â§à§ã§Ö§é§ß§Ñ §ã§ä§à§á§Ñ §á§à§Ó§Ö?§Ñ?§Ñ §Þ§à§ß§à§ä§à§ß§à §â§Ñ§ã§ä§å?§Ö§Ô §Ò§â§à?§Ñ§é§Ñ §å §ã§Ö§Ü§å§ß§Õ§Ú §å §à§Ü§Ó§Ú§â§å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §Ó§â§Ö§Þ§Ö§ß§ã§Ü§à§Ô §á§Ö§â§Ú§à§Õ§Ñ.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer.
§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:
§¶§å§ß§Ü§è§Ú§à§ß§Ñ§Ý§ß§à §à§Õ§Ô§à§Ó§Ñ§â§Ñ '' §à§Õ PromQL.
§±§â§Ú§Þ§Ö§â:
rate(/host/key,30s) #if the monotonic increase over 30 seconds is 20, this function will return 0.67.
§±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §ã§Ó§Ö §á§à§Õ§â§Ø§Ñ§ß§Ö §æ§å§ß§Ü§è§Ú?§Ö.