You can write any function that takes two parameters in both infix and prefix form. For example, you can use contains in prefix form like a function:
contains(filename, ".exe")or you can use it in infix form like an operator:
filename contains ".exe"The only functions or operators that have special treatment are the logical AND and OR. These can be written using Java-like && and ||, or as and and or. They can be used in infix form with two parameters:
srcip == 10.0.0.0/8 && dstip != 10.0.0.0/8
srcip == 10.0.0.0/8 and dstip != 10.0.0.0/8Or they can be written in prefix form, where they can have as many parameters as desired.
or(srcip == 10.0.0.0/8, srcip == 172.16.0.0/12, srcip == 192.168.0.0/16)
||(srcip == 10.0.0.0/8, srcip == 172.16.0.0/12, srcip == 192.168.0.0/16)You can also use list syntax for both AND and OR:
srcip == [10.0.0.0/8, 172.16.0.0.12, 192.168.0.0/16]
&[srcip, dstip] != 10.0.0.0/8Lists can also be used on both sides of a comparison, where:
&[srcip, dstip] != &[10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16]Is equivalent to:
(srcip != 10.0.0.0/8 && srcip != 172.16.0.0/12 && srcip != 192.168.0.0/16) && (dstip != 10.0.0.0/8 && dstip != 172.16.0.0/12 && dstip != 192.168.0.0/16)Although these examples only include single constants in the lists, you can use any expression inside a list.
You can use the NOT operator, ! or not, to invert a boolean. For example:
!(srcip == 10.0.0.0/8 || srcip == 192.168.0.0/16)In filter expressions, you can use the not operator with constants and with the list form of the AND or OR. If you use the not operator with a constant, the operator inverts the value of the constant. The following example checks if srcport has any value except for 80:
srcport == !80Similarly, when used with a list, the not operator inverts the meaning. For example, the following will match any srcip within 10.0.0.0/8 except 10.0.0.1 and 10.0.0.2:
srcip == [10.0.0.0/8, ![10.0.0.1, 10.0.0.2]]
srcip == 10.0.0.0/8 && !(srcip == 10.0.0.1 || srcip == 10.0.0.2)The following sections lists the types of functions you can use when you create or edit a rule.
Logical functions
The following table describes the supported logical functions.
Function | Name | Input parameter type | Output parameter type | Infix examples | Prefix examples |
|---|---|---|---|---|---|
&& | And | boolean | boolean | true && true | &&(true, true, true, true) |
|| | Or | boolean | boolean | true || true | ||(true, true, true, false) |
! | Not | boolean | boolean | Not applicable | !true |
Integer functions
The following table describes the supported integer functions.
Function | Name | Input parameter types | Output parameter type | Infix example | Prefix example |
|---|---|---|---|---|---|
== | Equal to | integer and integer | boolean | 1 == 2 | ==(1, 2) |
== | Equal to | integer and integer_range | boolean | 1 == 1 -> 10 | ==(1, 1 -> 10) |
!= | Not equal to | integer and integer | boolean | 1 != 2 | !=(1, 2) |
!= | Not equal to | integer and integer_range | boolean | 1 != 10 -> 12 | !=(1, 10 -> 12) |
< | Less than | integer and integer | boolean | 1 < 2 | <(1, 2) |
<= | Less than or equal to | integer and integer | boolean | 1 <= 2 | <=(1, 2) |
> | Greater than | integer and integer | boolean | 2 > 1 | >(2, 1) |
>= | Greater than or equal to | integer and integer | boolean | 2 >= 1 | >=(2, 1) |
-> | Range | integer and integer | integer_range | 1 -> 100 | ->(1, 100) |
+ | Add | integer and integer | integer | 1 + 1 | +(1, 1) |
- | Subtract | integer and integer | integer | 1 - 1 | -(1, 1) |
* | Multiply | integer and integer | integer | 1 * 2 | *(1, 2) |
/ | Divide | integer and integer | integer | 2 / 2 | /(2, 2) |
& | And | integer and integer | integer | 0xff & 1 | &(0xff, 1) |
| | Or | integer and integer | integer | 0xfe | 1 | |(0xfe, 1) |
^ | Index | integer and integer | integer | 0xff ^ 0xa5 | ^(0xff, 0xa5) |
string | String | string | string | Not applicable | string(123) |
Float functions
The following table describes the supported float functions.
Function | Name | Infix example | Prefix example |
|---|---|---|---|
== | Equal to | 1 == 2 | ==(1, 2) |
== | Equal to | 1 == 1 -> 10 | ==(1, 1 -> 10) |
!= | Not equal to | 1 != 2 | !=(1, 2) |
!= | Not equal to | 1 != 10 -> 12 | !=(1, 10 -> 12) |
< | Less than | 1 < 2 | <(1, 2) |
<= | Less than or equal to | 1 <= 2 | <=(1, 2) |
> | Greater than | 2 > 1 | >(2, 1) |
>= | Greater than or equal to | 2 >= 1 | >=(2, 1) |
-> | Range | 1 -> 100 | ->(1, 100) |
+ | Add | 1 + 1 | +(1, 1) |
- | Subtract | 1 - 1 | -(1, 1) |
* | Multiply | 1 * 2 | *(1, 2) |
/ | Divide | 2 / 2 | /(2, 2) |
& | And | 0xff & 1 | &(0xff, 1) |
| | Or | 0xfe | 1 | |(0xfe, 1) |
string | String | Not applicable | string(3.14) |
String functions
The following table describes the supported string functions.
Function | Name | Infix example | Prefix example |
|---|---|---|---|
== | Equal to | "abc" == "abc" | ==("abc", "abc") |
== | Equal to | "abc" == /[a-z]+/i | ==("abc", /[a-z]+/i) |
== | Equal to | /[a-z]+/i == "abc" | ==(/[a-z]/i, "abc") |
=~ | Equal to. Not case sensitive. | "abc" == "ABC" | ==("abc", "ABC") |
!= | Not equal to | "abc" != "ABC" | !=("abc", "ABC") |
!= | Not equal to | "abc" != /[0-9]+/ | !=("abc", /[0-9]+/) |
!= | Not equal to | /[0-9]+/ != "abc" | !=(/[0-9]+/, "abc") |
!~ | Not equal to. Not case sensitive. | "abc" != "123" | !=("abc", "123") |
< | Less than | "abc" < "def" | <("abc", "def") |
<= | Less than or equal to | "abc" <= "def" | <=("abc", "def") |
> | Greater than | "abc" > "def" | >("abc", "def") |
>= | Greater than or equal to | "abc" >= "def" | >=("abc", "def") |
<~ | Less than. Not case sensitive. | "abc" <~ "def" | <~("abc", "def") |
<=~ | Less than or equal to. Not case sensitive. | "abc" <=~ "def" | <=~("abc", "def") |
>~ | Greater than. Not case sensitive. | "abc" >~ "def" | >~("abc", "def") |
>=~ | Greater than or equal to. Not case sensitive. | "abc" >=~ "def" | >=~("abc", "def") |
+ | Add | "abc" + "def" | +("abc", "def") |
capture | "a@b.com" capture "/[^@]+@(.*)/,1" | capture("a@b.com", /[^@]+@(.*)/, 1) | |
jsonpath | "{\"field\":\"value\"}" jsonpath "$.field" | jsonpath("{\"field\":\"value\"}", "$.field") | |
contains | "abc" contains "b" | contains("abc", "b") | |
containsNoCase | "abc" containsNoCase "B" | containsNoCase("abc", "B") | |
startsWith | "abc" startsWith "a" | startsWith("abc", "a") | |
startsWithNoCase | "abc" startsWithNoCase "A" | startsWithNoCase("abc", "A") | |
endsWith | "abc" endsWith "c" | endsWith("abc", "c") | |
endsWithNoCase | "abc" endsWithNoCase "C" | endsWithNoCase("abc", "C") | |
length | Not applicable | length("abc") | |
indexOf | "abc" indexOf "bc" | indexOf("abc", "bc") | |
indexOfNoCase | "abc" indexOfNoCase "BC" | indexOfNoCase("abc", "BC") | |
replace | Not applicable | replace("something", "some", "other") | |
substring | "abc" substring 1 | substring("abc", 1) | |
substring | Not applicable | substring("abc", 1, 2) | |
strip | Not applicable | strip(" abc ") | |
strip | "[{(abc)}]" strip "[]{}()" | strip("[{(abc)}]", "[]{}()") | |
distance | "abc" distance "xbc" | distance("abc", "xbc") | |
md5 | Not applicable | md5("abcd") | |
md5 | Not applicable | md5("abcd", "base64") The second parameter is the output format, which can be either "hex" or "base64". | |
sha1 | Not applicable | sha1("abcd") | |
sha1 | Not applicable | sha256("abcd", "base64") The second parameter is the output format, which can be either "hex" or "base64". | |
sha256 | Not applicable | sha1("abcd") | |
sha256 | Not applicable | sha256("abcd", "base64") The second parameter is the output format, which can be either "hex" or "base64". | |
sha384 | Not applicable | sha384("abcd") | |
sha384 | Not applicable | sha384("abcd", "base64") The second parameter is the output format, which can be either "hex" or "base64". | |
sha512 | Not applicable | sha512("abcd") | |
sha512 | Not applicable | sha512("abcd", "base64") The second parameter is the output format, which can be either "hex" or "base64". | |
integer | Not applicable | integer("123") | |
float | Not applicable | float("3.14") | |
ip | Not applicable | ip("::1") | |
boolean | Not applicable | boolean("true") |
IP address functions
The following table describes the supported IP address functions.
Function | Name | Infix example | Prefix example |
|---|---|---|---|
== | Equal to | 10.0.0.1 == ::1 | ==(10.0.0.1, ::1) |
== | Equal to | 10.0.0.1 == 10.0.0.1 -> 10.0.0.2 | ==(10.0.0.1, 10.0.0.1 -> 10.0.0.2) |
!= | Not equal to | 10.0.0.1 != ::1 | !=(10.0.0.1, ::1) |
!= | Not equal to | 10.0.0.1 != 10.0.0.1 -> 10.0.0.2 | !=(10.0.0.1, 10.0.0.1 -> 10.0.0.2) |
-> | Range | 10.0.0.1 -> 10.0.0.3 | ->(10.0.0.1, 10.0.0.3) |
first | Not applicable | first(10.0.0.0/8) | |
last | Not applicable | last(10.0.0.0/8) | |
string | Not applicable | string(::1) | |
integer | Not applicable | integer(10.0.0.1) |
Aggregate functions
The following table describes the supported aggregate functions. All arguments used in each function must be of the same type.
Function | Input parameter types | Example | Description |
|---|---|---|---|
count | boolean, datetime, integer, IP, float, and string | count(event_type == "account created") as numCreated count(srcip, dstip) > 1 | Takes one or more arguments and returns the number of those arguments with non-null values. If the arguments are boolean values, then they must also be true to be counted. If any of the arguments are arrays, then the individual array values are counted. |
first | boolean, integer, IP, float, and string | first(username) as user first(username, targetusername, callingusername) | Takes one or more arguments, scans them in order, and returns the first one with a non-null value. If any of the arguments are arrays, then the individual array values are tested, and a single item from the array is returned. |
last | boolean, integer, IP, float, and string | last(username) as user last(username, targetusername, callingusername) | Takes one or more arguments, scans them in order, and returns the last one with a non-null value. If any of the arguments are arrays, then the individual array values are tested, and a single item from the array is returned. |
max | boolean, integer, IP, float, and string | max(size) as minSize | Takes one or more arguments, compares their values, and returns the one with the highest value. If one or more of the arguments are arrays, then each value in the array is compared. |
min | boolean, integer, IP, float, and string | min(size) as minSize | Takes one or more arguments, compares their values, and returns the one with the lowest value. If one or more of the arguments are arrays, then each value in the array is compared. |
sum | integer and float | Takes one or more arguments and sums all non-null values. If one or more arguments are arrays, then the individual array elements are summed. |
Date functions
The following table describes the supported date functions.
Function | Name | Infix example | Prefix example |
|---|---|---|---|
date | Date | Not applicable | date("2024-01-01") |
== | Equal to | time_field == date("this week") | Not applicable |
!= | Not equal to | time_field != date("today") | Not applicable |
> | Less than | time_field > date("15 days ago") | Not applicable |
>= | Less than or equal to | time_field >= date("last week") | Not applicable |
< | Greater than | time_field < date("this year") | Not applicable |
<= | Greater than or equal to | time_field <= date("last year") | Not applicable |
The following table describes the supported date formats.
Date format | Description |
|---|---|
yyyy-mm-dd | ISO date format without time that produces a time range covering the whole of the day described |
yyyy-MM-ddTHH:mm:ss yyyy-MM-dd HH:mm:ss | ISO date and time format that produces a time range covering the whole second described |
now | The current time |
today | A time range covering all of the current day from 00:00:00 to 23:59:59 |
yesterday | A time range covering all of yesterday |
this hour | A time range covering all of the current hour |
prev hour | A time range covering all of the previous hour |
last hour | A time range spanning from (now - 1 hour) to now |
this day | A time range covering all of today (equivalent to "today") |
prev day | A time range covering all of yesterday (equivalent to "yesterday") |
last day | A time range covering the previous 24 hours (from now-24h to now) |
this week | A time range covering all of the current week |
prev week | A time range covering all of the previous week |
last week | A time range covering the previous 7 days |
this month | A time range covering all of the current month |
prev month | A time range covering all of the previous month |
last month | A time range covering now-one month to now |
this year | A time range covering the whole of the current year |
prev year | A time range covering the whole of the previous year |
last year | A time range from now-365 days to now |
1 hour ago / X hours ago | Tests a time from an event against the specified age |
1 day ago / X days ago | Tests a time from an event against the specified age |
1 week ago / X weeks ago | Tests a time from an event against the specified age |
1 month ago / X month ago | Tests a time from an event against the specified age |
1 year ago / X years ago | Tests a time from an event against the specified age |
Miscellaneous functions
The following table describes the supported miscellaneous functions.
Function | Infix example | Prefix example |
|---|---|---|
has | Not applicable | has("fieldname") Returns a value of true if fieldname exists |
field | Not applicable | field("fieldname") Returns the value of fieldname. This is required if the parameter name is the same as a function name. field("fieldname", integer) Returns the value of fieldname and converts it to an integer. |
inWatchlist | "abc" inWatchlist "listname" 123 inWatchlist "listname" 10.0.0.1 inWatchlist "listname" Checks if the value defined is in listname. | inWatchlist("abc", "listname") inWatchlist("abc", "listname") inWatchlist(10.0.0.1, "listname") Checks if the value defined is in listname. |