Text search operators :: Kloudfuse Docs

Text search operators

Line contains (|=)

Keeps log lines that contain the given string anywhere in the line. This is the LogQL equivalent of grep: fast, case-sensitive, and the workhorse of interactive log exploration. Chain several filters to narrow results step by step.

Syntax

{<selector>} |= "<string>"

Parameters

Parameter Required Description
<string> Required The substring to search for. Matching is case-sensitive; no regex interpretation is applied.

Example

Find all POST requests handled by the nginx ingress controller.

{source="nginx"} |= "POST"

Expected output

10.20.15.233 - - [04/Jul/2026:15:38:16 +0000] "POST /ingester/otlp/v1/logs HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry C ...
10.20.15.210 - - [04/Jul/2026:15:38:16 +0000] "POST /ingester/otlp/metrics HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry C ...
10.20.15.217 - - [04/Jul/2026:15:38:16 +0000] "POST /ingester/otlp/v1/logs HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry C ...

Line does not contain (!=)

Discards log lines that contain the given string. Use it to peel away known noise — health checks, expected traffic, or messages you have already investigated — so the unexpected lines stand out.

Syntax

{<selector>} != "<string>"

Parameters

Parameter Required Description
<string> Required Lines containing this substring are removed from the result.

Example

Show POST traffic while hiding the high-volume log-ingestion endpoint, leaving the less common POST routes.

{source="nginx"} |= "POST" != "/ingester/otlp/v1/logs"

Expected output

10.20.15.192 - - [04/Jul/2026:15:38:20 +0000] "POST /ingester/otlp/metrics HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry C ...
10.20.15.211 - - [04/Jul/2026:15:38:20 +0000] "POST /ingester/otlp/metrics HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry C ...
10.20.15.200 - - [04/Jul/2026:15:38:20 +0000] "POST /ingester/otlp/metrics HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry C ...

Pattern not match (!>)

Discards log lines that match a pattern expression. Use it to exclude a well-known line shape — such as all GET requests — while keeping everything else.

Syntax

{<selector>} !> "<pattern>"

Parameters

Parameter Required Description
<pattern> Required A pattern expression; lines that fully match are removed. <_> matches any text.

Example

Drop all GET requests from the nginx access log, keeping POST, PUT, DELETE, and other methods.

{source="nginx"} !> "<_>\"GET <_>"

Expected output

10.20.15.218 - - [04/Jul/2026:15:38:36 +0000] "POST /ingester/otlp/metrics HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry C ...
10.20.15.211 - - [04/Jul/2026:15:38:36 +0000] "POST /ingester/otlp/metrics HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry C ...
10.20.15.234 - - [04/Jul/2026:15:38:36 +0000] "POST /ingester/otlp/v1/logs HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry C ...

Line regex not match (!~)

Discards log lines that match an RE2 regular expression. Use it to exclude several patterns at once with alternation, which is more compact than chaining multiple != filters.

Syntax

{<selector>} !~ "<regex>"

Parameters

Parameter Required Description
<regex> Required An RE2 regular expression, unanchored. Matching lines are removed.

Example

Hide routine INFO and DEBUG entries from ZooKeeper logs to surface warnings, errors, and unleveled output.

{source="zookeeper"} !~ "INFO|DEBUG"

Expected output

Removing file: Jul 4, 2026, 2:57:21?PM /bitnami/zookeeper/data/version-2/snapshot.277012cbbbf
Removing file: Jul 4, 2026, 2:59:46?PM /bitnami/zookeeper/data/version-2/snapshot.277012e1dfa
Removing file: Jul 4, 2026, 2:50:34?PM /bitnami/zookeeper/data/version-2/snapshot.2770128d5b4

Or (or)

Chains multiple values onto a single line filter so that a line matches if any value matches. The or keyword applies to all line filter types — contains, regex, and pattern — and keeps queries readable when matching several alternatives.

Syntax

{<selector>} |= "<string1>" or "<string2>" [or "<string3>" ...]

Parameters

Parameter Required Description
<stringN> Required Two or more filter values. The line is kept (or dropped, for negated filters) when any value matches.

Example

Keep nginx lines containing either mutating HTTP method. The result is equivalent to the regex filter |~ "POST|PUT" but uses cheaper substring matching.

{source="nginx"} |= "POST" or "PUT"

Expected output

10.20.0.17 - - [04/Jul/2026:15:38:42 +0000] "POST /ingester/otlp/metrics HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry Col ...
10.150.25.1 - - [04/Jul/2026:15:38:42 +0000] "POST /ingester/otlp/metrics HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry Co ...
10.20.15.213 - - [04/Jul/2026:15:38:42 +0000] "POST /ingester/otlp/v1/logs HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry C ...

Pattern match (|>)

Keeps log lines that match a pattern expression. Patterns use the literal text of the line with <_> as a wildcard for any run of characters, giving grep-like power without regex escaping. This is often the most readable way to match structured plain-text formats such as access logs.

Syntax

{<selector>} |> "<pattern>"

Parameters

Parameter Required Description
<pattern> Required A pattern expression. Literal text must match exactly; each <_> matches any text. The pattern must match the entire line.

Example

Match nginx access-log lines whose quoted request section starts with POST, without writing a regex.

{source="nginx"} |> "<_>\"POST <_>"

Expected output

10.2.140.127 - - [04/Jul/2026:15:38:33 +0000] "POST /write HTTP/1.1" 200 0 "-" "vmagent" 5099 0.012 [kfuse-ingester-8090 ...\
10.2.128.131 - - [04/Jul/2026:15:38:33 +0000] "POST /ingester/v1/fluent_bit HTTP/1.1" 200 0 "-" "Fluent-Bit" 835 0.012 [ ...\
10.2.134.34 - - [04/Jul/2026:15:38:33 +0000] "POST /ingester/v1/fluent_bit HTTP/1.1" 200 0 "-" "Fluent-Bit" 929 0.011 [k ...\

Line regex match (|~)

Keeps log lines that match an RE2 regular expression. Unlike stream-selector regex matchers, line filter expressions are not anchored — the pattern can match anywhere in the line. Use it when a plain substring is not expressive enough.

Syntax

{<selector>} |~ "<regex>"

Parameters

Parameter Required Description
<regex> Required An RE2 regular expression, unanchored. Escape backslashes inside the double-quoted string (write \\d for a digit class) or use backticks to avoid escaping.

Example

Match lines for either mutating HTTP method with one alternation.

{source="nginx"} |~ "POST|PUT"

Expected output

10.20.10.105 - - [04/Jul/2026:15:38:27 +0000] "POST /ingester/otlp/metrics HTTP/2.0" 200 2 "-" "OpenTelemetry Collector  ...
10.20.15.212 - - [04/Jul/2026:15:38:27 +0000] "POST /ingester/otlp/metrics HTTP/2.0" 200 2 "-" "OpenTelemetry Collector  ...
10.20.10.120 - - [04/Jul/2026:15:38:27 +0000] "POST /ingester/otlp/v1/logs HTTP/2.0" 200 2 "-" "ZSOS 42  OpenTelemetry C ...