如何在EQL查询中定义正则表达式以识别以点(.)开头的文件名?我的EQL查询报错,正则表达式存在什么问题?
Problem Context
I'm testing an EQL query to identify filenames starting with a dot (.), but I'm hitting a parsing error when executing it.
My Query:
GET /*/_eql/search { "query": """process where event.type in ("start", "process_started") and process.args: [/\.[a-zA-Z0-9_\-][a-zA-Z0-9_\-\.]{1,254}/] and process.name not in ("ls", "find") """ }
Error Response:
{ "error" : { "root_cause" : [ { "type" : "parsing_exception", "reason" : "line 2:17: no viable alternative at input 'process.args: ['" } ], "type" : "parsing_exception", "reason" : "line 2:17: no viable alternative at input 'process.args: ['", "caused_by" : { "type" : "no_viable_alt_exception", "reason" : null } }, "status" : 400 }
I want to know what's wrong with my regex, and how to correctly define a regex in EQL to target dot-started filenames.
Solution & Explanation
First: Fix the EQL Syntax Error
The parsing error you're seeing has nothing to do with your regex logic—it's because you're using square brackets [] around the regex, which isn't valid EQL syntax.
In EQL:
- Square brackets
[]are used for array value matching (e.g.,process.name in ("ls", "find")checks if the value is in that list). - For regex matching, you just need to write
field_name: /your-regex/directly, no brackets needed.
Second: Minor Regex Optimization
Your regex logic is mostly correct, but you can simplify the character groups:
- Instead of escaping the hyphen with
\-, just place it at the end of the character group (like[a-zA-Z0-9_-]). This works because hyphens don't need escaping when they're at the start/end of a character class, and it makes the regex easier to read.
Corrected Query
Here's the fixed EQL query:
GET /*/_eql/search { "query": """process where event.type in ("start", "process_started") and process.args: /\.[a-zA-Z0-9_-][a-zA-Z0-9_-\.]{1,254}/ and process.name not in ("ls", "find") """ }
Regex Breakdown
Let's break down what this regex does:
\.: Matches the leading dot (the\escapes the dot, since dot is a special regex character that matches any character by default).[a-zA-Z0-9_-]: Ensures there's at least one valid character right after the dot (prevents matching just a single.).[a-zA-Z0-9_-\.]{1,254}: Matches 1 to 254 additional valid filename characters (letters, numbers, underscores, hyphens, and dots—covering common hidden file naming patterns like.bashrcor.config.yaml).
Optional: Full Match vs Partial Match
If you need to ensure the entire process.args value is a dot-started filename (not just a substring within the argument), add start (^) and end ($) anchors to the regex:
/^\.[a-zA-Z0-9_-][a-zA-Z0-9_-\.]{1,254}$/
Use this only if you're targeting arguments that are exactly the hidden filename (e.g., ./.bashrc would not match this, but .bashrc would).
内容的提问来源于stack exchange,提问作者Milbatta Sannata

