Áú»¢¶Ä²©

4 §¶§å§ß§Ü§è§Ú?§Ö §Ú§ã§ä§à§â§Ú?§Ö

§³§Ó§Ö §æ§å§ß§Ü§è§Ú?§Ö §ß§Ñ§Ó§Ö§Õ§Ö§ß§Ö §à§Ó§Õ§Ö §ã§å §á§à§Õ§â§Ø§Ñ§ß§Ö §å:

§¶§å§ß§Ü§è§Ú?§Ö §ã§å §ß§Ñ§Ó§Ö§Õ§Ö§ß§Ö §Ò§Ö§Ù §Õ§à§Õ§Ñ§ä§ß§Ú§ç §Ú§ß§æ§à§â§Þ§Ñ§è§Ú?§Ñ. §¬§Ý§Ú§Ü§ß§Ú§ä§Ö §ß§Ñ §æ§å§ß§Ü§è§Ú?§å §Õ§Ñ §Ò§Ú§ã§ä§Ö §Ó§Ú§Õ§Ö§Ý§Ú §ã§Ó§Ö §Õ§Ö§ä§Ñ?§Ö.

Function Description
change §ª§Ù§ß§à§ã §â§Ñ§Ù§Ý§Ú§Ü§Ö §Ú§Ù§Þ§Ö?§å §á§â§Ö§ä§ç§à§Õ§ß§Ö §Ú §ß§Ñ?§ß§à§Ó§Ú?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú.
changecount §¢§â§à? §á§â§à§Þ§Ö§ß§Ñ §Ú§Ù§Þ§Ö?§å §ã§å§ã§Ö§Õ§ß§Ú§ç §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å§ß§å§ä§Ñ§â §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
count §¢§â§à? §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å§ß§å§ä§Ñ§â §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
countunique §¢§â§à? ?§Ö§Õ§Ú§ß§ã§ä§Ó§Ö§ß§Ú§ç §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å§ß§å§ä§Ñ§â §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
find §±§â§à§ß§Ñ§Ý§Ñ§Ø§Ö?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä §Ü§à?§Ñ §ã§Ö §á§à§Õ§å§Õ§Ñ§â§Ñ §å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Þ §á§Ö§â§Ú§à§Õ§å §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
first §±§â§Ó§Ñ (§ß§Ñ?§ã§ä§Ñ§â§Ú?§Ñ) §Ó§â§Ö§Õ§ß§à§ã§ä §å§ß§å§ä§Ñ§â §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
fuzzytime §±§â§à§Ó§Ö§â§Ñ §Ü§à§Ý§Ú§Ü§à §ã§Ö §Ó§â§Ö§Þ§Ö §á§Ñ§ã§Ú§Ó§ß§à§Ô §Ñ§Ô§Ö§ß§ä§Ñ §â§Ñ§Ù§Ý§Ú§Ü§å?§Ö §à§Õ §Ó§â§Ö§Þ§Ö§ß§Ñ Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ/§á§â§à§Ü§ã§Ú?§Ñ.
last §¯§Ñ?§ß§à§Ó§Ú?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä.
logeventid §±§â§à§Ó§Ö§â§Ñ §Õ§Ñ §Ý§Ú §ã§Ö ID §Õ§à§Ô§Ñ?§Ñ?§Ñ §á§à§ã§Ý§Ö§Õ?§Ö§Ô §å§ß§à§ã§Ñ §å §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ú §á§à§Õ§å§Õ§Ñ§â§Ñ §ã§Ñ §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§Þ §Ú§Ù§â§Ñ§Ù§à§Þ.
logseverity §°§Ù§Ò§Ú?§ß§à§ã§ä §á§à§ã§Ý§Ö§Õ?§Ö§Ô §å§ß§à§ã§Ñ §å §Õ§ß§Ö§Ó§ß§Ú§Ü.
logsource §±§â§à§Ó§Ö§â§Ñ §Õ§Ñ §Ý§Ú §Ú§Ù§Ó§à§â §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ö §á§à§ã§Ý§Ö§Õ?§Ö§Ô §å§ß§à§ã§Ñ §å §Õ§ß§Ö§Ó§ß§Ú§Ü §à§Õ§Ô§à§Ó§Ñ§â§Ñ §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Þ §Ú§Ù§â§Ñ§Ù§å.
monodec §±§â§à§Ó§Ö§â§Ú§ä§Ö §Õ§Ñ §Ý§Ú ?§Ö §Õ§à§ê§Ý§à §Õ§à §Þ§à§ß§à§ä§à§ß§à§Ô §ã§Þ§Ñ?§Ö?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú.
monoinc §±§â§à§Ó§Ö§â§Ú§ä§Ö §Õ§Ñ §Ý§Ú ?§Ö §Õ§à§ê§Ý§à §Õ§à §Þ§à§ß§à§ä§à§ß§à§Ô §á§à§Ó§Ö?§Ñ?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú.
nodata §±§â§à§Ó§Ö§â§Ú §Õ§Ñ §Ý§Ú §ß§Ö§Þ§Ñ §á§â§Ú§Þ?§Ö§ß§Ú§ç §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ.
percentile P-§ä§Ú §á§Ö§â§è§Ö§ß§ä§Ú§Ý §á§Ö§â§Ú§à§Õ§Ñ, §Ô§Õ§Ö ?§Ö P (§á§â§à§è§Ö§ß§Ñ§ä) §à§Õ§â§Ö?§Ö§ß §ä§â§Ö?§Ú§Þ §á§Ñ§â§Ñ§Þ§Ö§ä§â§à§Þ.
rate §±§â§à§ã§Ö§é§ß§Ñ §ã§ä§à§á§Ñ §á§à §ã§Ö§Ü§å§ß§Õ§Ú §á§à§Ó§Ö?§Ñ?§Ñ §å §Þ§à§ß§à§ä§à§ß§à §â§Ñ§ã§ä§å?§Ö§Þ §Ò§â§à?§Ñ§é§å §å §à§Ü§Ó§Ú§â§å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §Ó§â§Ö§Þ§Ö§ß§ã§Ü§à§Ô §á§Ö§â§Ú§à§Õ§Ñ.
§©§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú
  • /host/key ?§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ú §à§Ò§Ñ§Ó§Ö§Ù§ß§Ú §á§â§Ó§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â §Ù§Ñ §æ§å§ß§Ü§è§Ú?§Ö §Ü§à?§Ö §ã§Ö §â§Ö§æ§Ö§â§Ö§ß§è§Ú§â§Ñ?§å §ß§Ñ §Ú§ã§ä§à§â§Ú?§å §ã§ä§Ñ§Ó§Ü§Ö §Õ§à§Þ§Ñ?§Ú§ß§Ñ
  • (sec|#num)<:time shift> ?§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ú §Õ§â§å§Ô§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â §Ù§Ñ §æ§å§ß§Ü§è§Ú?§Ö §Ü§à?§Ö §å§á§å?§å?§å §ß§Ñ §Ú§ã§ä§à§â§Ú?§å §ã§ä§Ñ§Ó§Ü§Ö §Õ§à§Þ§Ñ?§Ú§ß§Ñ, §Ô§Õ§Ö ?§Ö: - sec - §Þ§Ñ§Ü§ã§Ú§Þ§å§Þ §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö §å §ã§Ö§Ü§å§ß§Õ§Ñ§Þ§Ñ (§Þ§à§Ô§å §ã§Ö §Ü§à§â§Ú§ã§ä§Ú§ä§Ú §Ó§â§Ö§Þ§Ö §ã§å§æ§Ú§Ü§ã§Ú) §Ú§Ý§Ú - #num - §Þ§Ñ§Ü§ã§Ú§Þ§å§Þ §à§á§ã§Ö§Ô §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö §å §ß§Ñ?§ß§à§Ó§Ú?§Ö§Þ §á§â§Ú§Ü§å§á?§Ñ?§å §Ó§â§Ö§Õ§ß§à§ã§ä§Ú (§Ñ§Ü§à §Ú§Þ §á§â§Ö§ä§ç§à§Õ§Ú §ç§Ö§ê §à§Ù§ß§Ñ§Ü§Ñ) - time shift (§à§á§è§Ú§à§ß§à) §à§Þ§à§Ô§å?§Ñ§Ó§Ñ §á§à§Þ§Ö§â§Ñ?§Ö §ä§Ñ§é§Ü§Ö §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö §ß§Ñ§Ù§Ñ§Õ §å §Ó§â§Ö§Þ§Ö. §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ó§Ú§ê§Ö §Õ§Ö§ä§Ñ?§Ñ §Ù§Ñ §ß§Ñ§Ó§à?§Ö?§Ö §Ó§â§Ö§Þ§Ö§ß§ã§Ü§à§Ô §á§à§Þ§Ö§â§Ñ?§Ñ.

§¥§Ö§ä§Ñ?§Ú §æ§å§ß§Ü§è§Ú?§Ö

§¯§Ö§Ü§Ö §à§á§ê§ä§Ö §ß§Ñ§á§à§Þ§Ö§ß§Ö §à §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú§Þ§Ñ §æ§å§ß§Ü§è§Ú?§Ö:

  • §±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú §æ§å§ß§Ü§è§Ú?§Ö §ã§å §à§Õ§Ó§à?§Ö§ß§Ú §Ù§Ñ§â§Ö§Ù§à§Þ
  • §°§á§è§Ú§à§ß§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú §æ§å§ß§Ü§è§Ú?§Ö (§Ú§Ý§Ú §Õ§Ö§Ý§à§Ó§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â§Ñ) §ã§å §à§Ù§ß§Ñ§é§Ö§ß§Ú §ã§Ñ < >
  • §±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú §ã§á§Ö§è§Ú§æ§Ú§é§ß§Ú §Ù§Ñ §æ§å§ß§Ü§è§Ú?§å §à§á§Ú§ã§Ñ§ß§Ú §ã§å §å§Ù §ã§Ó§Ñ§Ü§å §æ§å§ß§Ü§è§Ú?§å
  • /host/key §Ú (sec|#num)<:time shift> §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú §ß§Ú§Ü§Ñ§Õ§Ñ §ß§Ö §ã§Þ§Ö?§å §Ò§Ú§ä§Ú §á§à§Õ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ
change(/host/key)

§ª§Ù§ß§à§ã §â§Ñ§Ù§Ý§Ú§Ü§Ö §Ú§Ù§Þ§Ö?§å §á§â§Ö§ä§ç§à§Õ§ß§Ö §Ú §ß§Ñ?§ß§à§Ó§Ú?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.
§©§Ñ §ã§ä§â§Ú§ß§Ô§à§Ó§Ö §Ó§â§Ñ?§Ñ: 0 - §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §ã§å ?§Ö§Õ§ß§Ñ§Ü§Ö; 1 - §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §ã§Ö §â§Ñ§Ù§Ý§Ú§Ü§å?§å.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú: §á§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú.

§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:

  • §¯§å§Þ§Ö§â§Ú§é§Ü§Ñ §â§Ñ§Ù§Ý§Ú§Ü§Ñ ?§Ö §Ò§Ú§ä§Ú §Ú§Ù§â§Ñ§é§å§ß§Ñ§ä§Ñ, §Ü§Ñ§à §ê§ä§à §ã§Ö §Ó§Ú§Õ§Ú §ã§Ñ §à§Ó§Ú§Þ §Õ§à§Ý§Ñ§Ù§ß§Ú§Þ §á§â§Ú§Þ§Ö§â§Ú§Þ§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú ('previous' §Ú 'latest' §Ó§â§Ö§Õ§ß§à§ã§ä = §â§Ñ§Ù§Ý§Ú§Ü§Ñ):
    '1' §Ú '5' = +4
    '3' §Ú '1' = -2
    '0' §Ú '-2.5' = -2.5
  • §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §ä§Ñ§Ü§à?§Ö: abs §Ù§Ñ §á§à§â§Ö?§Ö?§Ö.

§±§â§Ú§Þ§Ö§â§Ú:

change(/host/key)>10
changecount(/host/key,(sec|#num)<:time shift>,<mode>)

§¢§â§à? §á§â§à§Þ§Ö§ß§Ñ §Ú§Ù§Þ§Ö?§å §ã§å§ã§Ö§Õ§ß§Ú§ç §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å §à§Ü§Ó§Ú§â§å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

  • §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ö;
  • mode (§Þ§à§â§Ñ §Ò§Ú§ä§Ú §á§à§Õ §Õ§Ó§à§ã§ä§â§å§Ü§Ú§Þ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ) - §Þ§à§Ô§å?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: all - §â§Ñ§é§å§ß§Ñ§ä§Ú §ã§Ó§Ö §á§â§à§Þ§Ö§ß§Ö (§á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à); dec - §Ò§â§à? §ã§Ö §ã§Þ§Ñ?§å?§Ö; inc - §Ò§â§à? §ã§Ö §á§à§Ó§Ö?§Ñ§Ó§Ñ

§©§Ñ §ß§Ö§ß§å§Þ§Ö§â§Ú§é§Ü§Ö §ä§Ú§á§à§Ó§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú, §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â mode §ã§Ö §Ù§Ñ§ß§Ö§Þ§Ñ§â§å?§Ö.

§±§â§Ú§Þ§Ö§â§Ú:

changecount(/host/key,1w) #the number of value changes for the last week until now
       changecount(/host/key,#10,"inc") #the number of value increases (relative to the adjacent value) among the last 10 values
       changecount(/host/key,24h,"dec") #the number of value decreases (relative to the adjacent value) for the last 24 hours until now
count(/host/key,(sec|#num)<:time shift>,<operator>,<pattern>)

§¢§â§à? §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å§ß§å§ä§Ñ§â §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §á§Ö§â§Ú§à§Õ§Ñ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

  • §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú;
  • §à§á§Ö§â§Ñ§ä§à§â (§Þ§à§â§Ñ §Ò§Ú§ä§Ú §á§à§Õ §Õ§Ó§à§ã§ä§â§å§Ü§Ú§Þ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ). §±§à§Õ§â§Ø§Ñ§ß§Ú operators:
    eq - ?§Ö§Õ§ß§Ñ§Ü§à (§á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à §Ù§Ñ integer, float)
    ne - §ß§Ú?§Ö ?§Ö§Õ§ß§Ñ§Ü§à
    * gt* - §Ó§Ö?§Ö §à§Õ
    ge - §Ó§Ö?§Ö §Ú§Ý§Ú ?§Ö§Õ§ß§Ñ§Ü§à
    * lt* - §Þ§Ñ?§Ö §à§Õ
    * le* - §Þ§Ñ?§Ö §Ú§Ý§Ú ?§Ö§Õ§ß§Ñ§Ü§à
    like (§á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à §Ù§Ñ string, text, log) - §à§Õ§Ô§à§Ó§Ñ§â§Ñ §Ñ§Ü§à §ã§Ñ§Õ§â§Ø§Ú §à§Ò§â§Ñ§Ù§Ñ§è (§â§Ñ§Ù§Ý§Ú§Ü§å?§Ö §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ)
    bitand - §Ò§Ú§ä§à§Ó§ã§Ü§à AND
    * regexp* - §á§à§Õ§å§Õ§Ñ§â§Ñ?§Ö §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ §Õ§Ñ§ä§à§Ô §å pattern §à§ã§Ö§ä?§Ú§Ó§à §ß§Ñ §Þ§Ñ§Ý§Ñ §Ú §Ó§Ö§Ý§Ú§Ü§Ñ §ã§Ý§à§Ó§Ñ
    * iregexp* - §á§à§Õ§å§Õ§Ñ§â§Ñ?§Ö §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ §Õ§Ñ§ä§à§Ô §å pattern §ß§Ö§à§ã§Ö§ä?§Ú§Ó§à §ß§Ñ §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ
  • ** pattern** - §Ù§Ñ§ç§ä§Ö§Ó§Ñ§ß§Ú §à§Ò§â§Ñ§Ù§Ñ§è (§Ñ§â§Ô§å§Þ§Ö§ß§ä§Ú §ã§ä§â§Ú§ß§Ô§à§Ó§Ñ §Þ§à§â§Ñ?§å §Ò§Ú§ä§Ú §á§à§Õ §Õ§Ó§à§ã§ä§â§å§Ü§Ú§Þ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ).

§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:

  • Float §ã§ä§Ñ§Ó§Ü§Ö §ã§Ö §á§à§Ü§Ý§Ñ§á§Ñ?§å §ã§Ñ §á§â§Ö§è§Ú§Ù§ß§à§ê?§å §à§Õ 2.22e-16;
  • like §ß§Ú?§Ö §á§à§Õ§â§Ø§Ñ§ß§à §Ü§Ñ§à §à§á§Ö§â§Ñ§ä§à§â §Ù§Ñ §è§Ö§Ý§à§Ò§â§à?§ß§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú;
    • like* §Ú * bitand* §ß§Ú§ã§å §á§à§Õ§â§Ø§Ñ§ß§Ú §Ü§Ñ§à §à§á§Ö§â§Ñ§ä§à§â§Ú §Ù§Ñ float §Ó§â§Ö§Õ§ß§à§ã§ä§Ú;
  • §©§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú string, text, §Ú log §á§à§Õ§â§Ø§Ñ§ß§Ú §ã§å §ã§Ñ§Þ§à §à§á§Ö§â§Ñ§ä§à§â§Ú eq, ne, like, regexp and iregexp;
  • §³§Ñ bitand §Ü§Ñ§à §à§á§Ö§â§Ñ§ä§à§â§à§Þ, §é§Ö§ä§Ó§â§ä§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â pattern §ã§Ö §Þ§à§Ø§Ö §ß§Ñ§Ó§Ö§ã§ä§Ú §Ü§Ñ§à §Õ§Ó§Ñ §Ò§â§à?§Ñ, §â§Ñ§Ù§Õ§Ó§à?§Ö§ß§Ñ §ã§Ñ '/': number_to_compare_with/mask. count() §Ú§Ù§â§Ñ§é§å§ß§Ñ§Ó§Ñ "§Ò§Ú§ä§à§Ó§ã§Ü§à AND" §Ú§Ù §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §Ú §Þ§Ñ§ã§Ü§Ö §Ú §å§á§à§â§Ö?§å?§Ö §â§Ö§Ù§å§Ý§ä§Ñ§ä §ã§Ñ §Ò§â§à?³å§Ù§Ñ³å§å§á§à§â§Ö?§Ú§Ó§Ñ?§Ö³å§ã§Ñ. §¡§Ü§à ?§Ö §â§Ö§Ù§å§Ý§ä§Ñ§ä "§Ò§Ú§ä§à§Ó§ã§Ü§à AND" ?§Ö§Õ§ß§Ñ§Ü number_to_compare_with, §Ó§â§Ö§Õ§ß§à§ã§ä §ã§Ö §â§Ñ§é§å§ß§Ñ.
    §¡§Ü§à §ã§å number_to_compare_with §Ú * mask* ?§Ö§Õ§ß§Ñ§Ü§Ú, §á§à§ä§â§Ö§Ò§ß§à ?§Ö §ã§Ñ§Þ§à §ß§Ñ§Ó§Ö§ã§ä§Ú mask (§Ò§Ö§Ù '/').
  • §³§Ñ regexp §Ú§Ý§Ú iregexp §Ü§Ñ§à §à§á§Ö§â§Ñ§ä§à§â§à§Þ, §é§Ö§ä§Ó§â§ä§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â pattern §Þ§à§Ø§Ö §Ò§Ú§ä§Ú §à§Ò§Ú§é§Ñ§ß §Ú§Ý§Ú §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú (§Ü§à?§Ú §á§à§é§Ú?§Ö §ã§Ñ '@') §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú §Ú§Ù§â§Ñ§Ù. §µ §ã§Ý§å§é§Ñ?§å §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú§ç §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§ç §Ú§Ù§â§Ñ§Ù§Ñ, §à§ã§Ö§ä?§Ú§Ó§à§ã§ä §ß§Ñ §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ §ã§Ö §ß§Ñ§ã§Ý§Ö?§å?§Ö §Ú§Ù §á§à§Õ§Ö§ê§Ñ§Ó§Ñ?§Ñ §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú§ç §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§ç §Ú§Ù§â§Ñ§Ù§Ñ. §©§Ñ §á§à§ä§â§Ö§Ò§Ö §á§à§Õ§å§Õ§Ñ§â§Ñ?§Ñ §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ, §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §ã§Ñ §á§à§Ü§â§Ö§ä§ß§Ú§Þ §Ò§â§à?§Ö§Þ §å§Ó§Ö§Ü ?§Ö §Ò§Ú§ä§Ú §á§â§Ö§Õ§ã§ä§Ñ§Ó?§Ö§ß§Ö §ã§Ñ 4 §Õ§Ö§è§Ú§Þ§Ñ§Ý§ß§Ö §è§Ú§æ§â§Ö §á§à§ã§Ý§Ö '.'. §´§Ñ§Ü§à?§Ö §Ú§Þ§Ñ?§ä§Ö §ß§Ñ §å§Þ§å §Õ§Ñ §Ù§Ñ §Ó§Ö§Ý§Ú§Ü§Ö §Ò§â§à?§Ö§Ó§Ö §â§Ñ§Ù§Ý§Ú§Ü§Ñ §å §Õ§Ö§è§Ú§Þ§Ñ§Ý§ß§à? (§é§å§Ó§Ñ§ß§à? §å §Ò§Ñ§Ù§Ú §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ) §Ú §Ò§Ú§ß§Ñ§â§ß§à? (§Ü§à?§å §Ü§à§â§Ú§ã§ä§Ú Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â) §Þ§à§Ø§Ö §å§ä§Ú§è§Ñ§ä§Ú §ß§Ñ 4. §Õ§Ö§è§Ú§Þ§Ñ§Ý§å.

§±§â§Ú§Þ§Ö§â§Ú:

count(/host/key,10m) #the values for the last 10 minutes until now
       count(/host/key,10m,"like","error") #the number of values for the last 10 minutes until now that contain 'error'
       count(/host/key,10m,,12) #the number of values for the last 10 minutes until now that equal '12'
       count(/host/key,10m,"gt",12) #the number of values for the last 10 minutes until now that are over '12'
       count(/host/key,#10,"gt",12) #the number of values within the last 10 values until now that are over '12'
       count(/host/key,10m:now-1d,"gt",12) #the number of values between 24 hours and 10 minutes and 24 hours ago from now that were over '12'
       count(/host/key,10m,"bitand","6/7") #the number of values for the last 10 minutes until now having '110' (in binary) in the 3 least significant bits
       count(/host/key,10m:now-1d) #the number of values between 24 hours and 10 minutes and 24 hours ago from now
countunique(/host/key,(sec|#num)<:time shift>,<operator>,<pattern>)

§¢§â§à? ?§Ö§Õ§Ú§ß§ã§ä§Ó§Ö§ß§Ú§ç §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Þ §á§Ö§â§Ú§à§Õ§å §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

  • §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ö;
  • §à§á§Ö§â§Ñ§ä§à§â (§Þ§à§â§Ñ §Ò§Ú§ä§Ú §á§à§Õ §Õ§Ó§à§ã§ä§â§å§Ü§Ú§Þ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ). §±§à§Õ§â§Ø§Ñ§ß§Ú operators:
    eq - ?§Ö§Õ§ß§Ñ§Ü§à (§á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à §Ù§Ñ integer, float)
    ne - §ß§Ú?§Ö ?§Ö§Õ§ß§Ñ§Ü§à
    gt - §Ó§Ö?§Ö §à§Õ
    * ge* - §Ó§Ö?§Ö §Ú§Ý§Ú ?§Ö§Õ§ß§Ñ§Ü§à §à§Õ
    lt - §Þ§Ñ?§Ö §à§Õ
    le - §Þ§Ñ?§Ö §Ú§Ý§Ú ?§Ö§Õ§ß§Ñ§Ü§à §à§Õ
    like (§á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à §Ù§Ñ string, text, log) - §à§Õ§Ô§à§Ó§Ñ§â§Ñ §Ñ§Ü§à §ã§Ñ§Õ§â§Ø§Ú §à§Ò§â§Ñ§Ù§Ñ§è (§â§Ñ§Ù§Ý§Ú§Ü§å?§Ö §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ)
    bitand - §Ò§Ú§ä§à§Ó§ã§Ü§à AND
    regexp - §á§à§Õ§å§Õ§Ñ§â§Ñ?§Ö §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ §Õ§Ñ§ä§à§Ô §å §å§Ù§à§â§è§å
    §Ú§â§Ö§Ô§Ö§Ü§á - §á§à§Õ§å§Õ§Ñ§â§Ñ?§Ö §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ §Õ§Ñ§ä§à§Ô §å pattern
    §Ò§Ö§Ù §à§Ò§Ù§Ú§â§Ñ §ß§Ñ §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ
  • §à§Ò§â§Ñ§Ù§Ñ§è - §Ù§Ñ§ç§ä§Ö§Ó§Ñ§ß§Ú §à§Ò§â§Ñ§Ù§Ñ§è (§Ñ§â§Ô§å§Þ§Ö§ß§ä§Ú §ã§ä§â§Ú§ß§Ô§à§Ó§Ñ §Þ§à§â§Ñ?§å §Ò§Ú§ä§Ú §á§à§Õ §Õ§Ó§à§ã§ä§â§å§Ü§Ú§Þ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ).

§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:

  • Float §ã§ä§Ñ§Ó§Ü§Ö §ã§Ö §á§à§Ü§Ý§Ñ§á§Ñ?§å §ã§Ñ §á§â§Ö§è§Ú§Ù§ß§à§ê?§å §à§Õ 2.22e-16;
    • like* §ß§Ú?§Ö §á§à§Õ§â§Ø§Ñ§ß§à §Ü§Ñ§à §à§á§Ö§â§Ñ§ä§à§â §Ù§Ñ §è§Ö§Ý§à§Ò§â§à?§ß§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú;
  • like §Ú bitand §ß§Ú§ã§å §á§à§Õ§â§Ø§Ñ§ß§Ú §Ü§Ñ§à §à§á§Ö§â§Ñ§ä§à§â§Ú §Ù§Ñ float §Ó§â§Ö§Õ§ß§à§ã§ä§Ú;
  • §©§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú string, text, §Ú log §á§à§Õ§â§Ø§Ñ§ß§Ú §ã§å §ã§Ñ§Þ§à eq, ne, like, regexp §Ú iregexp;
  • §³§Ñ bitand §Ü§Ñ§à §à§á§Ö§â§Ñ§ä§à§â§à§Þ, §é§Ö§ä§Ó§â§ä§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â pattern §ã§Ö §Þ§à§Ø§Ö §ß§Ñ§Ó§Ö§ã§ä§Ú §Ü§Ñ§à §Õ§Ó§Ñ §Ò§â§à?§Ñ, §â§Ñ§Ù§Õ§Ó§à?§Ö§ß§Ñ §ã§Ñ '/': number_to_compare_with/mask. countunique() §Ú§Ù§â§Ñ§é§å§ß§Ñ§Ó§Ñ "§Ò§Ú§ä§à§Ó§ã§Ü§à AND" §Ú§Ù §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §Ú §Þ§Ñ§ã§Ü§Ö §Ú §å§á§à§â§Ö?§å?§Ö §â§Ö§Ù§å§Ý§ä§Ñ§ä §ã§Ñ number_to_compare_with. §¡§Ü§à ?§Ö §â§Ö§Ù§å§Ý§ä§Ñ§ä "§Ò§Ú§ä§à§Ó§ã§Ü§à AND" ?§Ö§Õ§ß§Ñ§Ü number_to_compare_with, §Ó§â§Ö§Õ§ß§à§ã§ä §ã§Ö §â§Ñ§é§å§ß§Ñ.
    §¡§Ü§à §ã§å number_to_compare_with §Ú mask ?§Ö§Õ§ß§Ñ§Ü§Ú, §á§à§ä§â§Ö§Ò§ß§à ?§Ö §ã§Ñ§Þ§à §ß§Ñ§Ó§Ö§ã§ä§Ú mask (§Ò§Ö§Ù '/').
  • §³§Ñ regexp §Ú§Ý§Ú iregexp §Ü§Ñ§à §à§á§Ö§â§Ñ§ä§à§â§à§Þ, §é§Ö§ä§Ó§â§ä§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â pattern §Þ§à§Ø§Ö §Ò§Ú§ä§Ú §à§Ò§Ú§é§Ñ§ß §Ú§Ý§Ú §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú (§Ü§à?§Ú §á§à§é§Ú?§Ö §ã§Ñ '@') §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú §Ú§Ù§â§Ñ§Ù. §µ §ã§Ý§å§é§Ñ?§å §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú§ç §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§ç §Ú§Ù§â§Ñ§Ù§Ñ, §à§ã§Ö§ä?§Ú§Ó§à§ã§ä §ß§Ñ §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ §ã§Ö §ß§Ñ§ã§Ý§Ö?§å?§Ö §Ú§Ù §á§à§Õ§Ö§ê§Ñ§Ó§Ñ?§Ñ §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú§ç §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§ç §Ú§Ù§â§Ñ§Ù§Ñ. §©§Ñ §á§à§ä§â§Ö§Ò§Ö §á§à§Õ§å§Õ§Ñ§â§Ñ?§Ñ §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ, §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §ã§Ñ §á§Ý§å§ä§Ñ?§å?§Ú§Þ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú§Þ§Ñ ?§Ö §å§Ó§Ö§Ü §Ò§Ú§ä§Ú §á§â§Ö§Õ§ã§ä§Ñ§Ó?§Ö§ß§Ö §ã§Ñ 4 §Õ§Ö§è§Ú§Þ§Ñ§Ý§ß§Ö §è§Ú§æ§â§Ö §á§à§ã§Ý§Ö '.'. §´§Ñ§Ü§à?§Ö §Ú§Þ§Ñ?§ä§Ö §ß§Ñ §å§Þ§å §Õ§Ñ §Ù§Ñ §Ó§Ö§Ý§Ú§Ü§Ö §Ò§â§à?§Ö§Ó§Ö §â§Ñ§Ù§Ý§Ú§Ü§Ñ §å §Õ§Ö§è§Ú§Þ§Ñ§Ý§ß§à? (§é§å§Ó§Ñ§ß§à? §å §Ò§Ñ§Ù§Ú §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ) §Ú §Ò§Ú§ß§Ñ§â§ß§à? (§Ü§à?§å §Ü§à§â§Ú§ã§ä§Ú Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â) §Þ§à§Ø§Ö §å§ä§Ú§è§Ñ§ä§Ú §ß§Ñ 4. §Õ§Ö§è§Ú§Þ§Ñ§Ý§å.

§±§â§Ú§Þ§Ö§â§Ú:

countunique(/host/key,10m) #the number of unique values for the last 10 minutes until now
       countunique(/host/key,10m,"like","error") #the number of unique values for the last 10 minutes until now that contain 'error'
       countunique(/host/key,10m,,12) #the number of unique values for the last 10 minutes until now that equal '12'
       countunique(/host/key,10m,"gt",12) #the number of unique values for the last 10 minutes until now that are over '12'
       countunique(/host/key,#10,"gt",12) #the number of unique values within the last 10 values until now that are over '12'
       countunique(/host/key,10m:now-1d,"gt",12) #the number of unique values between 24 hours and 10 minutes and 24 hours ago from now that were over '12'
       countunique(/host/key,10m,"bitand","6/7") #the number of unique values for the last 10 minutes until now having '110' (in binary) in the 3 least significant bits
       countunique(/host/key,10m:now-1d) #the number of unique values between 24 hours and 10 minutes and 24 hours ago from now
find(/host/key,(sec|#num)<:time shift>,<operator>,<pattern>)

§±§â§à§ß§Ñ?§Ú§ä§Ö §á§à§Õ§å§Õ§Ñ§â§Ñ?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Þ §á§Ö§â§Ú§à§Õ§å §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.
§£§â§Ñ?§Ñ: 1 - §á§â§à§ß§Ñ?§Ö§ß§à; 0 - §Ú§ß§Ñ§é§Ö.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

  • §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §å§à§Ò§Ú§é§Ñ?§Ö§ß§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ö;
  • sec §Ú§Ý§Ú #num (§à§á§è§Ú§à§ß§à) - §á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§Ñ ?§Ö §ß§Ñ?§ß§à§Ó§Ú?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä §Ñ§Ü§à §ß§Ú?§Ö §ß§Ñ§Ó§Ö§Õ§Ö§ß§Ñ
  • operator (§Þ§à§â§Ñ §Ò§Ú§ä§Ú §á§à§Õ §Õ§Ó§à§ã§ä§â§å§Ü§Ú§Þ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ). §±§à§Õ§â§Ø§Ñ§ß§Ú operators:
    eq - ?§Ö§Õ§ß§Ñ§Ü§à (§á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à §Ù§Ñ integer, float)
    ne - §ß§Ú?§Ö ?§Ö§Õ§ß§Ñ§Ü§à
    gt - §Ó§Ö?§Ö §à§Õ
    ge - §Ó§Ö?§Ö §Ú§Ý§Ú ?§Ö§Õ§ß§Ñ§Ü§à
    lt - §Þ§Ñ?§Ö §à§Õ
    le - §Þ§Ñ?§Ö §Ú§Ý§Ú ?§Ö§Õ§ß§Ñ§Ü§à
    like (§á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à §Ù§Ñ string, text, log) - §à§Õ§Ô§à§Ó§Ñ§â§Ñ §Ñ§Ü§à §ã§Ñ§Õ§â§Ø§Ú §ã§ä§â§Ú§ß§Ô §Õ§Ñ§ä §å pattern (§à§ã§Ö§ä?§Ú§Ó§à §ß§Ñ §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ)
    * bitand* - §á§à §Ò§Ú§ä§à§Ó§ã§Ü§à§Þ AND
    * regexp* - §á§à§Õ§å§Õ§Ñ§â§Ñ?§Ö §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ §Õ§Ñ§ä§à§Ô §å pattern
    * iregexp* - §á§à§Õ§å§Õ§Ñ§â§Ñ?§Ö §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ §Ò§Ö§Ù §à§Ò§Ù§Ú§â§Ñ §ß§Ñ §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ §å pattern
  • ** pattern** - §ä§â§Ñ§Ø§Ö§ß§Ú §à§Ò§â§Ñ§Ù§Ñ§è (§Ñ§â§Ô§å§Þ§Ö§ß§ä§Ú §ã§ä§â§Ú§ß§Ô§à§Ó§Ñ §Þ§à§â§Ñ?§å §Ò§Ú§ä§Ú §á§à§Õ §Õ§Ó§à§ã§ä§â§å§Ü§Ú§Þ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ); (PCRE) §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú §Ú§Ù§â§Ñ§Ù §Ñ§Ü§à ?§Ö operator regexp, iregexp.

§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:

  • §¡§Ü§à §ã§Ö §à§Ò§â§Ñ§Õ§Ú §Ó§Ú§ê§Ö §à§Õ ?§Ö§Õ§ß§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú, '1' §ã§Ö §Ó§â§Ñ?§Ñ §Ñ§Ü§à §á§à§ã§ä§à?§Ú §Ò§Ñ§â ?§Ö§Õ§ß§Ñ §à§Õ§Ô§à§Ó§Ñ§â§Ñ?§å?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä;
  • like §ß§Ú?§Ö §á§à§Õ§â§Ø§Ñ§ß§à §Ü§Ñ§à §à§á§Ö§â§Ñ§ä§à§â §Ù§Ñ §è§Ö§Ý§à§Ò§â§à?§ß§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú;
  • like §Ú bitand §ß§Ú§ã§å §á§à§Õ§â§Ø§Ñ§ß§Ú §Ü§Ñ§à §à§á§Ö§â§Ñ§ä§à§â§Ú §Ù§Ñ float §Ó§â§Ö§Õ§ß§à§ã§ä§Ú;
  • §©§Ñ string, text, and log §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §á§à§Õ§â§Ø§Ñ§ß§Ú §ã§å §ã§Ñ§Þ§à §à§á§Ö§â§Ñ§ä§à§â§Ú eq, ne, like, regexp §Ú iregexp;
  • §³§Ñ regexp §Ú§Ý§Ú iregexp §Ü§Ñ§à §à§á§Ö§â§Ñ§ä§à§â§à§Þ, §é§Ö§ä§Ó§â§ä§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â pattern §Þ§à§Ø§Ö §Ò§Ú§ä§Ú §à§Ò§Ú§é§Ñ§ß §Ú§Ý§Ú §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú (§Ü§à?§Ú §á§à§é§Ú?§Ö §ã§Ñ '@') §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú §Ú§Ù§â§Ñ§Ù. §µ §ã§Ý§å§é§Ñ?§å §Ô§Ý§à§Ò§Ñ§Ý§ß§Ú§ç §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§ç §Ú§Ù§â§Ñ§Ù§Ñ, §à§ã§Ö§ä?§Ú§Ó§à§ã§ä §ß§Ñ §Ó§Ö§Ý§Ú§Ü§Ñ §Ú §Þ§Ñ§Ý§Ñ §ã§Ý§à§Ó§Ñ §ã§Ö §ß§Ñ§ã§Ý§Ö?§å?§Ö §Ú§Ù §á§à§Õ§Ö§ê§Ñ§Ó§Ñ?§Ñ §Ô§Ý§à§Ò§Ñ§Ý§ß§à§Ô §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Ô §Ú§Ù§â§Ñ§Ù§Ñ.

§±§â§Ú§Þ§Ö§â:

find(/host/key,10m,"like","error") #find a value that contains 'error' within the last 10 minutes until now
first(/host/key,sec<:time shift>)

§±§â§Ó§Ñ (§ß§Ñ?§ã§ä§Ñ§â§Ú?§Ñ) §Ó§â§Ö§Õ§ß§à§ã§ä §å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Þ §á§Ö§â§Ú§à§Õ§å §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

§´§Ñ§Ü§à?§Ö §á§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö last().

§±§â§Ú§Þ§Ö§â:

first(/host/key,1h) #retrieve the oldest value within the last hour until now
fuzzytime(/host/key,sec)

§±§â§à§Ó§Ö§â§Ú§ä§Ö §Ü§à§Ý§Ú§Ü§à §ã§Ö §Ó§â§Ö§Þ§Ö §á§Ñ§ã§Ú§Ó§ß§à§Ô §Ñ§Ô§Ö§ß§ä§Ñ §â§Ñ§Ù§Ý§Ú§Ü§å?§Ö §à§Õ §Ó§â§Ö§Þ§Ö§ß§Ñ Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ/§á§â§à§Ü§ã§Ú?§Ñ.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer.
§£§â§Ñ?§Ñ: 1 - §â§Ñ§Ù§Ý§Ú§Ü§Ñ §Ú§Ù§Þ§Ö?§å §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §á§Ñ§ã§Ú§Ó§ß§Ö §ã§ä§Ñ§Ó§Ü§Ö (§Ü§Ñ§à §Ó§â§Ö§Þ§Ö§ß§ã§Ü§Ö §à§Ù§ß§Ñ§Ü§Ö) §Ú §Ó§â§Ö§Þ§Ö§ß§ã§Ü§Ö §à§Ù§ß§Ñ§Ü§Ö Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ/§á§â§à§Ü§ã§Ú?§Ñ (§ã§Ñ§ä §á§â§Ú§Ü§å§á?§Ñ?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú) ?§Ö §Þ§Ñ?§Ñ §Ú§Ý§Ú ?§Ö§Õ§ß§Ñ§Ü§Ñ §à§Õ sec §ã§Ö§Ü§å§ß§Õ§Ú; 0 - §Ú§ß§Ñ§é§Ö.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:

  • §°§Ò§Ú§é§ß§à §ã§Ö §Ü§à§â§Ú§ã§ä§Ú §ã§Ñ §ã§ä§Ñ§Ó§Ü§à§Þ 'system.localtime' §Ù§Ñ §á§â§à§Ó§Ö§â§å §Õ§Ñ §Ý§Ú ?§Ö §Ý§à§Ü§Ñ§Ý§ß§à §Ó§â§Ö§Þ§Ö §ã§Ú§ß§ç§â§à§ß§Ú§Ù§à§Ó§Ñ§ß§à §ã§Ñ §Ý§à§Ü§Ñ§Ý§ß§Ú§Þ §Ó§â§Ö§Þ§Ö§ß§à§Þ Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ. §ª§Þ§Ñ?§ä§Ö §ß§Ñ §å§Þ§å §Õ§Ñ 'system.localtime' §Þ§à§â§Ñ §Ò§Ú§ä§Ú §Ü§à§ß§æ§Ú§Ô§å§â§Ú§ã§Ñ§ß§Ñ §Ü§Ñ§à §á§Ñ§ã§Ú§Ó§ß§Ñ §á§â§à§Ó§Ö§â§Ñ.
  • §®§à§Ø§Ö §ã§Ö §Ü§à§â§Ú§ã§ä§Ú§ä§Ú §Ú §ã§Ñ §Ü?§å§é§Ö§Þ vfs.file.time[/path/file,modify] §Õ§Ñ §ã§Ö §á§â§à§Ó§Ö§â§Ú §Õ§Ñ §Ý§Ú §Õ§Ñ§ä§à§ä§Ö§Ü§Ñ §ß§Ú?§Ö §Õ§à§Ò§Ú?§Ñ§Ý§Ñ §Ñ§Ø§å§â§Ú§â§Ñ?§Ñ §Õ§å§Ø§Ö §Ó§â§Ö§Þ§Ö;
  • §°§Ó§Ñ §æ§å§ß§Ü§è§Ú?§Ñ §ã§Ö §ß§Ö §á§â§Ö§á§à§â§å§é§å?§Ö §Ù§Ñ §Ü§à§â§Ú§ê?§Ö?§Ö §å §ã§Ý§à§Ø§Ö§ß§Ú§Þ §Ú§Ù§â§Ñ§Ù§Ú§Þ§Ñ §à§Ü§Ú§Õ§Ñ§é§Ñ (§ã§Ñ §å§Ü?§å§é§Ö§ß§Ú§Þ §Ó§Ú§ê§Ö §ã§ä§Ñ§Ó§Ü§Ú), ?§Ö§â §Þ§à§Ø§Ö §Õ§Ñ §Ú§Ù§Ñ§Ù§à§Ó§Ö §ß§Ö§à§é§Ö§Ü§Ú§Ó§Ñ§ß§Ö §â§Ö§Ù§å§Ý§ä§Ñ§ä§Ö (§Ó§â§Ö§Þ§Ö§ß§ã§Ü§Ñ §â§Ñ§Ù§Ý§Ú§Ü§Ñ ?§Ö §ã§Ö §Þ§Ö§â§Ú§ä§Ú §ß§Ñ?§ß§à§Ó§Ú?§à§Þ §Þ§Ö§ä§â§Ú§Ü§à§Þ), §ß§á§â., §å fuzzytime(/Host/system.localtime,60s)=0 or last(/Host/trap)<>0.

§±§â§Ú§Þ§Ö§â:

fuzzytime(/host/key,60s)=0 #§à§ä§Ü§â§Ú§Ó§Ñ §á§â§à§Ò§Ý§Ö§Þ §Ñ§Ü§à ?§Ö §Ó§â§Ö§Þ§Ö§ß§ã§Ü§Ñ §â§Ñ§Ù§Ý§Ú§Ü§Ñ §Ó§Ö?§Ñ §à§Õ 60 §ã§Ö§Ü§å§ß§Õ§Ú

last(/host/key,<#num<:time shift>>)

§¯§Ñ?§ß§à§Ó§Ú?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer, String, Text, Log.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:

  • §ª§Þ§Ñ?§ä§Ö §ß§Ñ §å§Þ§å §Õ§Ñ §Ó§â§Ö§Þ§Ö§ß§ã§Ü§Ú §á§Ö§â§Ú§à§Õ §à§Ù§ß§Ñ§é§Ö§ß §ç§Ö§ê§à§Þ (#N) §à§Ó§Õ§Ö §æ§å§ß§Ü§è§Ú§à§ß§Ú§ê§Ö §Õ§â§å§Ô§Ñ§é§Ú?§Ö §ß§Ö§Ô§à §Ü§à§Õ §Þ§ß§à§Ô§Ú§ç §Õ§â§å§Ô§Ú§ç §æ§å§ß§Ü§è§Ú?§Ñ. §¯§Ñ §á§â§Ú§Þ§Ö§â: last(/host/key) ?§Ö §å§Ó§Ö§Ü ?§Ö§Õ§ß§Ñ§Ü§à last(/host/key,#1); last(/host/key,#3) - §ä§â§Ö?§Ñ §ß§Ñ?§ß§à§Ó§Ú?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä (not §ä§â§Ú §á§à§ã§Ý§Ö§Õ?§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú);
  • Áú»¢¶Ä²© §ß§Ö §Ô§Ñ§â§Ñ§ß§ä§å?§Ö §ä§Ñ§é§Ñ§ß §â§Ö§Õ§à§ã§Ý§Ö§Õ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §Ñ§Ü§à §á§à§ã§ä§à?§Ú §Ó§Ú§ê§Ö §à§Õ §Õ§Ó§Ö §Ó§â§Ö§Õ§ß§à§ã§ä§Ú §å ?§Ö§Õ§ß§à? §ã§Ö§Ü§å§ß§Õ§Ú §å §Ú§ã§ä§à§â§Ú?§Ú;
  • §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §ä§Ñ§Ü§à?§Ö first().

§±§â§Ú§Þ§Ö§â:

last(/host/key) #retrieve the last value
       last(/host/key,#2) #retrieve the previous value
       last(/host/key,#1) <> last(/host/key,#2) #the last and previous values differ
logeventid(/host/key,<#num<:time shift>>,<pattern>)

§±§â§à§Ó§Ö§â§Ú§ä§Ö §Õ§Ñ §Ý§Ú §ã§Ö ID §Õ§à§Ô§Ñ?§Ñ?§Ñ §á§à§ã§Ý§Ö§Õ?§Ö§Ô §å§ß§à§ã§Ñ §å §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ú §á§à§Õ§å§Õ§Ñ§â§Ñ §ã§Ñ §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú§Þ §Ú§Ù§â§Ñ§Ù§à§Þ.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Log.
§£§â§Ñ?§Ñ: 0 - §ß§Ö §à§Õ§Ô§à§Ó§Ñ§â§Ñ; 1 - §à§Õ§Ô§à§Ó§Ñ§â§Ñ.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

  • §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú;
  • #num (§à§á§è§Ú§à§ß§à) - N-§ä§Ñ §ß§Ñ?§ß§à§Ó§Ú?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä;
  • pattern (§à§á§è§Ú§à§ß§à) - §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú §Ú§Ù§â§Ñ§Ù §Ü§à?§Ú §à§á§Ú§ã§å?§Ö §á§à§ä§â§Ö§Ò§Ñ§ß §à§Ò§â§Ñ§Ù§Ñ§è, §ã§ä§Ú§Ý (PCRE) (§ã§ä§â§Ú§ß§Ô §Ñ§â§Ô§å§Þ§Ö§ß§Ñ§ä§Ñ §Þ§à§â§Ñ §Ò§Ú§ä§Ú §á§à§Õ §Õ§Ó§à§ã§ä§â§å§Ü§Ú§Þ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ).
logseverity(/host/key,<#num<:time shift>>)

§°§Ù§Ò§Ú?§ß§à§ã§ä §Õ§ß§Ö§Ó§ß§Ú§Ü§Ñ §á§à§ã§Ý§Ö§Õ?§Ö§Ô §å§ß§à§ã§Ñ §å §Õ§ß§Ö§Ó§ß§Ú§Ü.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Log.
§£§â§Ñ?§Ñ: 0 - §á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§Ñ §à§Ù§Ò§Ú?§ß§à§ã§ä; N - §à§Ù§Ò§Ú?§ß§à§ã§ä (§è§Ö§à §Ò§â§à?, §Ü§à§â§Ú§ã§ß§à §Ù§Ñ Windows §Õ§à§Ô§Ñ?§Ñ?§Ö: 1 - §ª§ß§æ§à§â§Þ§Ñ§è§Ú?§Ö, 2 - §µ§á§à§Ù§à§â§Ö?§Ö, 4 - §¤§â§Ö§ê§Ü§Ñ, 7 - §¯§Ö§å§ã§á§Ö§Ý§Ñ §á§â§à§Ó§Ö§â§Ñ, 8 - §µ§ã§á§Ö§ê§ß§Ñ §á§â§à§Ó§Ö§â§Ñ, 9 - §¬§â§Ú§ä§Ú§é§ß§Ñ, 10 - §¥§Ö§ä§Ñ?§ß§à).

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

§©§Ñ§Ò§Ò§Ú§Ü §á§â§Ö§å§Ù§Ú§Þ§Ñ §à§Ù§Ò§Ú?§ß§à§ã§ä §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ö §Ú§Ù §á§à?§Ñ §ª§ß§æ§à§â§Þ§Ñ§è§Ú?§Ö Windows §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ.

logsource(/host/key,<#num<:time shift>>,<pattern>)

§±§â§à§Ó§Ö§â§Ñ§Ó§Ñ §Õ§Ñ §Ý§Ú §Ú§Ù§Ó§à§â §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ö §á§à§ã§Ý§Ö§Õ?§Ö§Ô §å§ß§à§ã§Ñ §Õ§ß§Ö§Ó§ß§Ú§Ü§Ñ §à§Õ§Ô§à§Ó§Ñ§â§Ñ §â§Ö§Ô§å§Ý§Ñ§â§ß§à§Þ §Ú§Ù§â§Ñ§Ù§å.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: * Log*.
§£§â§Ñ?§Ñ: 0 - §ß§Ö §à§Õ§Ô§à§Ó§Ñ§â§Ñ; 1 - §à§Õ§Ô§à§Ó§Ñ§â§Ñ.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

  • §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ö;
  • #num (§à§á§è§Ú§à§ß§à) - N-§ä§Ñ §ß§Ñ?§ß§à§Ó§Ú?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä;
  • ** pattern** (§à§á§è§Ú§à§ß§à) - §â§Ö§Ô§å§Ý§Ñ§â§ß§Ú §Ú§Ù§â§Ñ§Ù §Ü§à?§Ú §à§á§Ú§ã§å?§Ö §á§à§ä§â§Ö§Ò§Ñ§ß §à§Ò§â§Ñ§Ù§Ñ§è, (PCRE) §ã§ä§Ú§Ý (§ã§ä§â§Ú§ß§Ô §Ñ§â§Ô§å§Þ§Ö§ß§ä§Ú §Þ§à§â§Ñ?§å §Ò§Ú§ä§Ú §á§à§Õ §Õ§Ó§à§ã§ä§â§å§Ü§Ú§Þ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ).

§°§Ò§Ú§é§ß§à §ã§Ö §Ü§à§â§Ú§ã§ä§Ú §Ù§Ñ Windows §Ö§Ó§Ú§Õ§Ö§ß§è§Ú?§Ö §Õ§à§Ô§Ñ?§Ñ?§Ñ.

§±§â§Ú§Þ§Ö§â:

logsource(/host/key,,"VMware Server")
monodec(/host/key,(sec|#num)<:time shift>,<mode>)

§±§â§à§Ó§Ö§â§Ú§ä§Ö §Õ§Ñ §Ý§Ú ?§Ö §Õ§à§ê§Ý§à §Õ§à §Þ§à§ß§à§ä§à§ß§à§Ô §á§Ñ§Õ§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Integer.
§£§â§Ñ?§Ñ: 1 - §Ñ§Ü§à §ã§Ö §ã§Ó§Ú §Ö§Ý§Ö§Þ§Ö§ß§ä§Ú §å §Ó§â§Ö§Þ§Ö§ß§ã§Ü§à§Þ §á§Ö§â§Ú§à§Õ§å §Ü§à§ß§ä§Ú§ß§å§Ú§â§Ñ§ß§à §ã§Þ§Ñ?§å?§å; 0 - §Ú§ß§Ñ§é§Ö.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

  • §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú;
  • mode (§Þ§à§â§Ñ §Ò§Ú§ä§Ú §á§à§Õ §Õ§Ó§à§ã§ä§â§å§Ü§Ú§Þ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ) - weak (§ã§Ó§Ñ§Ü§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä ?§Ö §Þ§Ñ?§Ñ §Ú§Ý§Ú §Ú§ã§ä§Ñ §Ü§Ñ§à §á§â§Ö§ä§ç§à§Õ§ß§Ñ; §á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à) §Ú§Ý§Ú * strict* (§ã§Ó§Ñ§Ü§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä ?§Ö §ã§Þ§Ñ?§Ö§ß§Ñ).

§±§â§Ú§Þ§Ö§â:

monodec(/Host1/system.swap.size[all,free],60s) + monodec(/Host2/system.swap.size[all,free],60s) + monodec(/Host3/system.swap.size[all,free],60s) #calculate in how many hosts there has been a decrease in free swap size
monoinc(/host/key,(sec|#num)<:time shift>,<mode>)

§±§â§à§Ó§Ö§â§Ú§ä§Ö §Õ§Ñ §Ý§Ú ?§Ö §Õ§à§ê§Ý§à §Õ§à §Þ§à§ß§à§ä§à§ß§à§Ô §á§à§Ó§Ö?§Ñ?§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä§Ú.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: * Integer*.
§£§â§Ñ?§Ñ: 1 - §Ñ§Ü§à §ã§Ö §ã§Ó§Ú §Ö§Ý§Ö§Þ§Ö§ß§ä§Ú §å §Ó§â§Ö§Þ§Ö§ß§ã§Ü§à§Þ §á§Ö§â§Ú§à§Õ§å §Ü§à§ß§ä§Ú§ß§å§Ú§â§Ñ§ß§à §á§à§Ó§Ö?§Ñ§Ó§Ñ?§å; 0 - §Ú§ß§Ñ§é§Ö.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

  • §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ú;
  • mode (§Þ§à§â§Ñ §Ò§Ú§ä§Ú §á§à§Õ §Õ§Ó§à§ã§ä§â§å§Ü§Ú§Þ §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú§Þ§Ñ) - weak (§ã§Ó§Ñ§Ü§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä ?§Ö §Ó§Ö?§Ñ §Ú§Ý§Ú §Ú§ã§ä§Ñ §Ü§Ñ§à §á§â§Ö§ä§ç§à§Õ§ß§Ñ; §á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à) §Ú§Ý§Ú * strict* (§ã§Ó§Ñ§Ü§Ñ §Ó§â§Ö§Õ§ß§à§ã§ä ?§Ö §á§à§Ó§Ö?§Ñ§ß§Ñ).

§±§â§Ú§Þ§Ö§â:

monoinc(/Host1/system.localtime,#3,"strict")=0 #check if the system local time has been increasing consistently
nodata(/host/key,sec,<mode>)

§±§â§à§Ó§Ö§â§Ú§ä§Ö §Õ§Ñ §ß§Ö§Þ§Ñ §á§â§Ú§Þ?§Ö§ß§Ú§ç §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Integer, Float, Character, Text, Log.
§£§â§Ñ?§Ñ: 1 - §Ñ§Ü§à §ß§Ú§ã§å §á§â§Ú§Þ?§Ö§ß§Ú §á§à§Õ§Ñ§è§Ú §ä§à§Ü§à§Þ §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §Ó§â§Ö§Þ§Ö§ß§ã§Ü§à§Ô §á§Ö§â§Ú§à§Õ§Ñ; 0 - §Ú§ß§Ñ§é§Ö.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

  • §±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ù§Ñ?§Ö§Õ§ß§Ú§é§Ü§Ö §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ö;
  • sec - §á§Ö§â§Ú§à§Õ §ß§Ö §Ò§Ú §ä§â§Ö§Ò§Ñ§Ý§à §Õ§Ñ §Ò§å§Õ§Ö §Ü§â§Ñ?§Ú §à§Õ 30 §ã§Ö§Ü§å§ß§Õ§Ú ?§Ö§â §á§â§à§è§Ö§ã §ã§Ú§ß§ç§â§à§ß§Ú§Ù§Ñ§è§Ú?§Ö §Ú§ã§ä§à§â§Ú?§Ö §Ú§Ù§â§Ñ§é§å§ß§Ñ§Ó§Ñ §à§Ó§å §æ§å§ß§Ü§è§Ú?§å §ã§Ñ§Þ§à §ã§Ó§Ñ§Ü§Ú§ç 30 §ã§Ö§Ü§å§ß§Õ§Ú; nodata(/host/key,0) ?§Ö §ß§Ö§Õ§à§Ù§Ó§à?§Ö§ß§à.
  • ** mode** - §Ñ§Ü§à ?§Ö §á§à§ã§ä§Ñ§Ó?§Ö§ß§à §ß§Ñ strict (§Õ§Ó§à§ã§ä§â§å§Ü§Ú §ß§Ñ§Ó§à§Õ§ß§Ú§è§Ú), §à§Ó§Ñ §æ§å§ß§Ü§è§Ú?§Ñ ?§Ö §Ò§Ú§ä§Ú §ß§Ö§à§ã§Ö§ä?§Ú§Ó§Ñ §ß§Ñ §Õ§à§ã§ä§å§á§ß§à§ã§ä §á§â§à§Ü§ã§Ú?§Ñ (§á§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §Ü§à§Þ§Ö§ß§ä§Ñ§â§Ö §Ù§Ñ §Õ§Ö§ä§Ñ?§Ö).

§¬§à§Þ§Ö§ß§ä§Ñ§â§Ú:

  • §à§Ü§Ú§Õ§Ñ§é§Ú 'nodata' §Ü§à?§Ö §ß§Ñ§Õ§Ô§Ý§Ö§Õ§Ñ §á§â§à§Ü§ã§Ú §ã§å, §á§à§Õ§â§Ñ§Ù§å§Þ§Ö§Ó§Ñ§ß§à, §à§ã§Ö§ä?§Ú§Ó§Ú §ß§Ñ §Õ§à§ã§ä§å§á§ß§à§ã§ä §á§â§à§Ü§ã§Ú?§Ñ - §Ñ§Ü§à §á§â§à§Ü§ã§Ú §á§à§ã§ä§Ñ§ß§Ö §ß§Ö§Õ§à§ã§ä§å§á§Ñ§ß, §à§Ü§Ú§Õ§Ñ§é§Ú 'nodata' §ã§Ö §ß§Ö?§Ö §á§à§Ü§â§Ö§ß§å§ä§Ú §à§Õ§Þ§Ñ§ç §ß§Ñ§Ü§à§ß §à§Ò§ß§Ñ§Ó?§Ñ?§Ñ §Ó§Ö§Ù§Ö, §Ó§Ö? ?§Ö §á§â§Ö§ã§Ü§à§é§Ú§ä§Ú §á§à§Õ§Ñ§ä§Ü§Ö §Ù§Ñ §à§Õ§Ý§à§Ø§Ö§ß§Ú §á§Ö§â§Ú§à§Õ. §ª§Þ§Ñ?§ä§Ö §ß§Ñ §å§Þ§å §Õ§Ñ §ã§Ö §Ù§Ñ §á§Ñ§ã§Ú§Ó§ß§Ö §á§â§à§Ü§ã§Ú?§Ö §á§à§ä§Ú§ã§Ü§Ú§Ó§Ñ?§Ö §Ñ§Ü§ä§Ú§Ó§Ú§â§Ñ §Ñ§Ü§à §ã§Ö §Ó§Ö§Ù§Ñ §á§à§ß§à§Ó§à §å§ã§á§à§ã§ä§Ñ§Ó§Ú §Ù§Ñ §Ó§Ú§ê§Ö §à§Õ 15 §ã§Ö§Ü§å§ß§Õ§Ú §Ú §ß§Ö §Þ§Ñ?§Ö §à§Õ 2 §ã§Ö§Ü§å§ß§Õ§Ö §Ü§Ñ§ã§ß§Ú?§Ö. §©§Ñ §Ñ§Ü§ä§Ú§Ó§ß§Ö §á§â§à§Ü§ã§Ú?§Ö §ã§å§Ù§Ò§Ú?§Ñ?§Ö §ã§Ö §Ñ§Ü§ä§Ú§Ó§Ú§â§Ñ §Ñ§Ü§à §ã§Ö §Ó§Ö§Ù§Ñ §å§ã§á§à§ã§ä§Ñ§Ó§Ú §Ó§Ú§ê§Ö §à§Õ 15 §ã§Ö§Ü§å§ß§Õ§Ú §Ü§Ñ§ã§ß§Ú?§Ö. §¥§Ñ §Ò§Ú§ã§ä§Ö §Ú§ã§Ü?§å§é§Ú§Ý§Ú §à§ã§Ö§ä?§Ú§Ó§à§ã§ä §ß§Ñ §Õ§à§ã§ä§å§á§ß§à§ã§ä §á§â§à§Ü§ã§Ú?§Ñ, §Ü§à§â§Ú§ã§ä§Ú§ä§Ö §ä§â§Ö?§Ú §á§Ñ§â§Ñ§Þ§Ö§ä§Ñ§â, §ß§á§â.: nodata(/host/key,5m,"strict"); §å §à§Ó§à§Þ §ã§Ý§å§é§Ñ?§å §æ§å§ß§Ü§è§Ú?§Ñ ?§Ö §ã§Ö §á§à§Ü§â§Ö§ß§å§ä§Ú §é§Ú§Þ §á§â§à?§Ö §á§Ö§â§Ú§à§Õ §Ö§Ó§Ñ§Ý§å§Ñ§è§Ú?§Ö (§á§Ö§ä §Þ§Ú§ß§å§ä§Ñ) §Ò§Ö§Ù §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ.
  • §°§Ó§Ñ §æ§å§ß§Ü§è§Ú?§Ñ ?§Ö §á§â§Ú§Ü§Ñ§Ù§Ñ§ä§Ú §Ô§â§Ö§ê§Ü§å §Ñ§Ü§à §å §à§Ü§Ó§Ú§â§å §á§Ö§â§Ú§à§Õ§Ñ §á§â§Ó§à§Ô §á§Ñ§â§Ñ§Þ§Ö§ä§â§Ñ:
    - §ß§Ö§Þ§Ñ §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §Ú Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â ?§Ö §á§à§ß§à§Ó§à §á§à§Ü§â§Ö§ß§å§ä
    - §ß§Ö§Þ§Ñ §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §Ú §à§Õ§â§Ø§Ñ§Ó§Ñ?§Ö ?§Ö §Ù§Ñ§Ó§â§ê§Ö§ß§à
    - §ß§Ö§Þ§Ñ §á§à§Õ§Ñ§ä§Ñ§Ü§Ñ §Ú §ã§ä§Ñ§Ó§Ü§Ñ ?§Ö §Õ§à§Õ§Ñ§ä§Ñ §Ú§Ý§Ú §á§à§ß§à§Ó§à §à§Þ§à§Ô§å?§Ö§ß§Ñ
  • §¤§â§Ö§ê§Ü§Ö §ã§Ö §á§â§Ú§Ü§Ñ§Ù§å?§å §å §Ü§à§Ý§à§ß§Ú §ª§ß§æ§à§â§Þ§Ñ§è§Ú?§Ö §å §à§Ü§Ú§Õ§Ñ§é§å §Ü§à§ß§æ§Ú§Ô§å§â§Ñ§è§Ú?§Ñ;
  • §°§Ó§Ñ §æ§å§ß§Ü§è§Ú?§Ñ §Þ§à§Ø§Õ§Ñ §ß§Ö?§Ö §Ú§ã§á§â§Ñ§Ó§ß§à §â§Ñ§Õ§Ú§ä§Ú §Ñ§Ü§à §á§à§ã§ä§à?§Ö §Ó§â§Ö§Þ§Ö§ß§ã§Ü§Ö §â§Ñ§Ù§Ý§Ú§Ü§Ö §Ú§Ù§Þ§Ö?§å Áú»¢¶Ä²© §ã§Ö§â§Ó§Ö§â§Ñ, §á§â§à§Ü§ã§Ú?§Ñ §Ú §Ñ§Ô§Ö§ß§ä§Ñ. §´§Ñ§Ü§à?§Ö §á§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö: §µ§ã§Ý§à§Ó §Ù§Ñ §Ó§â§Ö§Þ§Ö§ß§ã§Ü§å §ã§Ú§ß§ç§â§à§ß§Ú§Ù§Ñ§è§Ú?§å;
  • §¶§å§ß§Ü§è§Ú?§Ñ nodata() §ã§Ö §ß§Ö §Þ§à§Ø§Ö §Ü§à§â§Ú§ã§ä§Ú§ä§Ú §å §Ú§Ù§â§Ñ§Ù§å §ã§Ñ§Þ§Ñ; §ß§Ñ?§Þ§Ñ?§Ö ?§Ö§Õ§ß§Ñ §æ§å§ß§Ü§è§Ú?§Ñ §Ú§Ù §Õ§â§å§Ô§Ö §Ô§â§å§á§Ö, §Ü§à?§Ñ §å§á§å?§å?§Ö §ß§Ñ §ã§ä§Ñ§Ó§Ü§å §Õ§à§Þ§Ñ?§Ú§ß§Ñ, §Þ§à§â§Ñ §Ò§Ú§ä§Ú §å§Ü?§å§é§Ö§ß§Ñ §å §Ú§Ù§â§Ñ§Ù (§à§ã§Ú§Þ §æ§å§ß§Ü§è§Ú?§Ñ §Ù§Ñ §Õ§Ñ§ä§å§Þ §Ú §Ó§â§Ö§Þ§Ö). §©§Ñ §Õ§Ö§ä§Ñ?§ß§Ö §Ú§ß§æ§à§â§Þ§Ñ§è§Ú?§Ö §à §ä§à§Þ§Ö §Ü§Ñ§Ü§à §æ§å§ß§Ü§è§Ú?§Ñ nodata() §æ§å§ß§Ü§è§Ú§à§ß§Ú§ê§Ö §å§ß§å§ä§Ñ§â §Ú§Ù§â§Ñ§Ù§Ñ, §á§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §£§â§Ö§Þ§Ö §Ú§Ù§â§Ñ§é§å§ß§Ñ§Ó§Ñ?§Ñ.
percentile(/host/key,(sec|#num)<:time shift>,percentage)

P-§ä§Ú §á§Ö§â§è§Ö§ß§ä§Ú§Ý §á§Ö§â§Ú§à§Õ§Ñ, §Ô§Õ§Ö ?§Ö P (§á§â§à§è§Ö§ß§Ñ§ä) §à§Õ§â§Ö?§Ö§ß §ä§â§Ö?§Ú§Þ §á§Ñ§â§Ñ§Þ§Ö§ä§â§à§Þ.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

rate(/host/key,sec<:time shift>)

§±§â§à§ã§Ö§é§ß§Ñ §ã§ä§à§á§Ñ §á§à§Ó§Ö?§Ñ?§Ñ §Þ§à§ß§à§ä§à§ß§à §â§Ñ§ã§ä§å?§Ö§Ô §Ò§â§à?§Ñ§é§Ñ §å §ã§Ö§Ü§å§ß§Õ§Ú §å §à§Ü§Ó§Ú§â§å §Õ§Ö§æ§Ú§ß§Ú§ã§Ñ§ß§à§Ô §Ó§â§Ö§Þ§Ö§ß§ã§Ü§à§Ô §á§Ö§â§Ú§à§Õ§Ñ.
§±§à§Õ§â§Ø§Ñ§ß§Ú §ä§Ú§á§à§Ó§Ú §Ó§â§Ö§Õ§ß§à§ã§ä§Ú: Float, Integer.

§±§Ñ§â§Ñ§Þ§Ö§ä§â§Ú:

§¶§å§ß§Ü§è§Ú§à§ß§Ñ§Ý§ß§à §à§Õ§Ô§à§Ó§Ñ§â§Ñ '' §à§Õ PromQL.

§±§â§Ú§Þ§Ö§â:

rate(/host/key,30s) #if the monotonic increase over 30 seconds is 20, this function will return 0.67.

§±§à§Ô§Ý§Ö§Õ§Ñ?§ä§Ö §ã§Ó§Ö §á§à§Õ§â§Ø§Ñ§ß§Ö §æ§å§ß§Ü§è§Ú?§Ö.