Search Query Language
In this section, we'll introduce the following concepts:
data:image/s3,"s3://crabby-images/d3e2e/d3e2ef038c0d7840df71d107a3c728f276f8e64c" alt="icon showing magnifying glass hovering over a data symbol"
Search Operators
Available search operators in the Sumo Logic search query language.
data:image/s3,"s3://crabby-images/d3e2e/d3e2ef038c0d7840df71d107a3c728f276f8e64c" alt="icon showing magnifying glass hovering over a data symbol"
Parse Operators
Sumo Logic provides a number of ways to parse fields in your log messages.
data:image/s3,"s3://crabby-images/d3e2e/d3e2ef038c0d7840df71d107a3c728f276f8e64c" alt="icon showing magnifying glass hovering over a data symbol"
Group or Aggregate Operators
Evaluate messages and place them into groups.
data:image/s3,"s3://crabby-images/d3e2e/d3e2ef038c0d7840df71d107a3c728f276f8e64c" alt="icon showing magnifying glass hovering over a data symbol"
Field Expressions
Overview of the expressions that create user-defined numeric, boolean, or string fields.
data:image/s3,"s3://crabby-images/d3e2e/d3e2ef038c0d7840df71d107a3c728f276f8e64c" alt="icon showing magnifying glass hovering over a data symbol"
Math Expressions
Use general mathematical expressions on numerical data extracted from log lines.
data:image/s3,"s3://crabby-images/d3e2e/d3e2ef038c0d7840df71d107a3c728f276f8e64c" alt="icon showing magnifying glass hovering over a data symbol"
Transaction Analytics
Find and group related log data.
Syntax style​
Sumo Logic search query language syntax is written in the following styles.
Code Font​
Search syntax, queries, parameters, and filenames are displayed in Regular Code Font
.
Required and optional arguments:
- A required argument is wrapped in angle brackets
< >
. - An optional argument is wrapped in square brackets
[ ]
.
Example:
| parse [field=<field_name>] "<start_anchor>*<stop_anchor>" as <field> [nodrop]
The required arguments are <start_anchor>
, <stop_anchor>
, and <field>
.
The optional arguments are [field=<field_name>]
and the [nodrop]
option.
One or more arguments:
- An argument that can be specified more than once has an ellipsis ... to indicate where you may add additional arguments.
Example:
concat(<field1>, <field2>[, <field3>, ...]) as <field>
data:image/s3,"s3://crabby-images/ccb40/ccb4093258a877e6c0e9f64563c2ac7f6c513050" alt=""
For a collection of customer-created search queries and their use cases, see the Community Query Library.