Match expressions are Java-like expressions that examine the fields of an item and return a result. They are most commonly used in fields conditions, where they return a boolean result that indicates if the events fields match or not.
You can also use match expressions to produce the groupby value in a correlation rule. The groupby parameter is a comma-separated list of expressions, each of which can produce any type of result. If you use a match expression with the groupby parameter, the expression is normally a single field name, or a list of names. For example, the single field called username, or the comma-separated list of field names srcip, destip. However, match expressions can use any feature of the rule language. Each part of the groupby result is joined using a separator character, for example srcip, dstip could return a result of 10.0.0.1|10.0.0.2.
Finally, you can use match expressions in the output section of a rule to define the value of a field you want to add to a generated event. In this case, the expression can return any type of result.
The following table describes the types of values you can use in match expressions:
Parameter | Description | Format |
|---|---|---|
string | A string |
|
integer | A 64 bit signed integer number |
|
integer_range | A range of 64 bit signed integer numbers | None, see '->' range operator in Rule functions and operators |
float | A double precision floating point number |
|
float_range | A range of double precision floating point numbers | None, see '->' range operator in Rule functions and operators |
boolean | A boolean |
|
ip | A CIDR IP address range |
|
ip_range | A range of IP addresses | None, see '->' range operator in Rule functions and operators |
regex | A regular expression (RE2 variant) |
|