Comparison operators :: Kloudfuse Docs
Comparison operators
Equal (=)
Selects log streams whose label value is exactly equal to the given string. This is the most common matcher and the fastest, because it resolves directly against the label index. Every LogQL query needs at least one non-empty matcher in its stream selector.
Syntax
{<label>="<value>"}
Parameters
| Parameter | Required | Description |
|---|---|---|
<label> |
Required | An indexed stream label, such as source, level, host, or kube_namespace. |
<value> |
Required | The exact string to match. Comparison is case-sensitive. |
Example
Select all log lines from the nginx ingress controller. Each returned line is a raw nginx access-log entry.
{source="nginx"}
Expected output
10.150.4.1 - - [04/Jul/2026:15:38:04 +0000] "POST /v1/input HTTP/2.0" 200 0 "-" "datadog-agent/7.79.1" 3920 0.013 [kfuse ...\
10.150.4.1 - - [04/Jul/2026:15:38:04 +0000] "POST /ingester/intake/ HTTP/2.0" 200 0 "-" "datadog-agent/7.79.1" 12476 0.0 ...\
10.20.0.44 - - [04/Jul/2026:15:38:04 +0000] "POST /v1/input HTTP/2.0" 200 0 "-" "datadog-agent/7.79.1" 26081 0.026 [kfus ...\
Not equal (!=)
Selects log streams whose label value is not equal to the given string. Use it to exclude one stream from an otherwise broad selection — for example, all log levels except error while investigating what happened before failures.
Syntax
{<label>="<value>", <label2>!="<value2>"}
Parameters
| Parameter | Required | Description |
|---|---|---|
<label> |
Required | The stream label to test. |
<value> |
Required | The string value to exclude. Comparison is case-sensitive. |
Example
Select Grafana logs at every level except error. The result contains info, warn, and debug lines only.
{source="grafana", level!="error"}
Expected output
logger=ngalert.state.manager rule_uid=bfoy7tneurcw0f org_id=1 t=2026-07-04T15:38:05.346683129Z level=info msg="Detected ...\
logger=ngalert.state.manager rule_uid=bfoy7tneurcw0f org_id=1 t=2026-07-04T15:38:05.346756834Z level=info msg="Detected ...\
logger=ngalert.state.manager rule_uid=deer5zpvjivpdf org_id=1 t=2026-07-04T15:38:05.314430324Z level=info msg="Detected ...\
Regex not match (!~)
Selects log streams whose label value does not match an RE2 regular expression. Use it to exclude several values with one matcher — for example, dropping both debug and info noise in a single expression.
Syntax
{<label>="<value>", <label2>!~"<regex>"}
Parameters
| Parameter | Required | Description |
|---|---|---|
<label> |
Required | The stream label to test. |
<regex> |
Required | An RE2 regular expression. Streams where the entire label value matches are excluded. |
Example
Select Grafana logs while excluding the chatty debug and info levels, leaving warn and error lines.
{source="grafana", level!~"debug|info"}
Expected output
logger=ngalert.state.manager rule_uid=ffls7hdn4xsshd org_id=1 t=2026-07-04T15:38:08.312822406Z level=error msg="Error in ...\
logger=ngalert.state.manager rule_uid=ffls7hdn4xsshd org_id=1 t=2026-07-04T15:38:08.312940088Z level=error msg="Error in ...\
logger=ngalert.state.manager rule_uid=ffls7hdn4xsshd org_id=1 t=2026-07-04T15:38:08.314370235Z level=error msg="Error in ...\
Regex match (=~)
Selects log streams whose label value matches an RE2 regular expression. The expression is fully anchored: it must match the entire label value, so nginx.* matches nginx and nginx-fips but gin matches nothing. Use it to select a family of related streams in one query.
Syntax
{<label>=~"<regex>"}
Parameters
| Parameter | Required | Description |
|---|---|---|
<label> |
Required | The stream label to test. |
<regex> |
Required | An RE2 regular expression. The match is anchored at both ends of the label value. |
Example
Select logs from every nginx variant at once — both the nginx and nginx-fips ingress controllers match the expression.
{source=~"nginx.*"}
Expected output
10.20.10.114 - - [04/Jul/2026:15:38:10 +0000] "POST /ingester/api/v1/filebeat/_bulk HTTP/1.1" 200 4854 "-" "Elastic-file ...\
10.20.15.199 - - [04/Jul/2026:15:38:10 +0000] "POST /ingester/otlp/v1/logs HTTP/2.0" 200 2 "-" "ZSOS 42 OpenTelemetry C ...\
10.20.15.230 - - [04/Jul/2026:15:38:10 +0000] "POST /ingester/otlp/metrics HTTP/2.0" 200 2 "-" "ZSOS 42 OpenTelemetry C ...\