如何在Graylog中搜索含空格的目标子串(如does not exist)?
问题描述
使用Graylog收集OpenShift集群日志时,需要筛选namespace_name为foo、container_name为bar的容器中,包含字符串“does not exist”的错误日志,但多次尝试查询均未得到预期结果:
- 首次查询仅匹配完全等于“does not exist”的日志,无法匹配包含该子串的长日志:
message: "does not exist" and namespace_name: "foo" and container_name: "bar"
实际日志格式示例:Object .... with ID .... does not exist. Error-code ....
- 带通配符/正则但加双引号的查询无效,因为双引号内内容会被原样解析,通配符不生效:
message: "*does not exist*" and namespace_name: "foo" and container_name: "bar" message: ".*does not exist.*" and namespace_name: "foo" and container_name: "bar"
- 去掉双引号后的查询仍无效,原因是“not”被当作逻辑否定运算符,查询逻辑被错误解析:
message: *does not exist* and namespace_name: "foo" and container_name: "bar" message: .*does not exist.* and namespace_name: "foo" and container_name: "bar"
可行查询方案
方案1:用match_phrase匹配完整短语
通过match_phrase明确指定匹配连续完整的短语,避免“not”被误判为逻辑词:
match_phrase(message: "does not exist") and namespace_name: "foo" and container_name: "bar"
该方式会精准匹配消息字段中包含“does not exist”连续子串的日志。
方案2:用括号将短语作为整体包裹
用括号把带空格的短语括起来,强制查询引擎将其视为一个完整搜索项:
message:(does not exist) and namespace_name: "foo" and container_name: "bar"
也可以保留双引号结合括号,效果一致:
message:("does not exist") and namespace_name: "foo" and container_name: "bar"
方案3:使用regex函数正则匹配
如果需要更灵活的匹配(允许短语前后有任意字符),用regex函数明确声明正则表达式:
regex(message, ".*does not exist.*") and namespace_name: "foo" and container_name: "bar"
此方式会匹配消息中任意位置包含“does not exist”子串的日志,解决了直接写正则不生效的问题。
内容的提问来源于stack exchange,提问作者mmo
相关产品推荐
相关产品推荐

