pub enum CompiledMatcher {
Show 23 variants
Exact {
value: String,
case_insensitive: bool,
},
Contains {
value: String,
case_insensitive: bool,
},
StartsWith {
value: String,
case_insensitive: bool,
},
EndsWith {
value: String,
case_insensitive: bool,
},
Regex(Regex),
AhoCorasickSet {
automaton: AhoCorasick,
case_insensitive: bool,
needles: Vec<String>,
},
RegexSetMatch {
set: RegexSet,
mode: GroupMode,
},
Cidr(IpNet),
NumericEq(f64),
NumericGt(f64),
NumericGte(f64),
NumericLt(f64),
NumericLte(f64),
Exists(bool),
FieldRef {
field: String,
case_insensitive: bool,
},
Null,
BoolEq(bool),
Expand {
template: Vec<ExpandPart>,
case_insensitive: bool,
},
TimestampPart {
part: TimePart,
inner: Box<CompiledMatcher>,
},
Not(Box<CompiledMatcher>),
AnyOf(Vec<CompiledMatcher>),
AllOf(Vec<CompiledMatcher>),
CaseInsensitiveGroup {
children: Vec<CompiledMatcher>,
mode: GroupMode,
},
}Expand description
A pre-compiled matcher for a single value comparison.
All string matchers store their values in the form needed for comparison
(Unicode-lowercased for case-insensitive). The case_insensitive flag
controls whether the input is lowercased before comparison.
Variants§
Exact
Exact string equality.
Contains
Substring containment.
StartsWith
String starts with prefix.
EndsWith
String ends with suffix.
Regex(Regex)
Compiled regex pattern (flags baked in at compile time).
AhoCorasickSet
Multi-pattern substring match via Aho-Corasick automaton.
Built by the optimizer when an AnyOf group contains
AHO_CORASICK_THRESHOLD or more plain Contains matchers with the
same case sensitivity. Replaces the sequential O(N * haystack_len)
scan of AnyOf([Contains, ...]) with a single linear pass.
Invariant: this variant only encodes AnyOf (OR) semantics.
AllOf(Contains) (|all modifier) MUST NOT be collapsed into this
variant - the optimizer enforces this.
Case insensitivity: when case_insensitive is true, needles are
stored pre-lowered (matching the Contains invariant) and the hot
path lowers the haystack via ascii_lowercase_cow before searching.
The AhoCorasick automaton itself is built case-sensitively.
Fields
automaton: AhoCorasickneedles: Vec<String>Pre-lowered needles in the same order they were fed to
AhoCorasick::new. Retained so downstream consumers (e.g. the
engine’s per-field bloom builder) can recover the pattern set
without parsing the automaton’s internal state.
RegexSetMatch
Multi-pattern regex match via regex::RegexSet.
Built by the optimizer when an AnyOf group contains
REGEX_SET_THRESHOLD or more individual Regex matchers. Compiles
every pattern into a single combined DFA so one traversal of the
haystack tests all patterns at once.
Pattern reconstruction: the optimizer rebuilds the set from each
matcher’s Regex::as_str, which preserves any inline flags the
compiler inlined (e.g. (?i), (?ims)). This relies on the eval
crate’s regex builder always inlining flags into the pattern string
rather than configuring them via RegexBuilder. A unit test guards
against future drift in that contract.
Cidr(IpNet)
CIDR network match for IP addresses.
NumericEq(f64)
Numeric equality.
NumericGt(f64)
Numeric greater-than.
NumericGte(f64)
Numeric greater-than-or-equal.
NumericLt(f64)
Numeric less-than.
NumericLte(f64)
Numeric less-than-or-equal.
Exists(bool)
Field existence check. true = field must exist, false = must not exist.
FieldRef
Compare against another field’s value.
Null
Match null / missing values.
BoolEq(bool)
Boolean equality.
Expand
Placeholder expansion: %fieldname% is resolved from the event at match time.
TimestampPart
Extract a time component from a timestamp field value and match it.
Not(Box<CompiledMatcher>)
Negated matcher: matches if the inner matcher does NOT match.
AnyOf(Vec<CompiledMatcher>)
Match if ANY child matches (OR).
AllOf(Vec<CompiledMatcher>)
Match if ALL children match (AND).
CaseInsensitiveGroup
A composite of case-insensitive string matchers that lowers the haystack once before dispatching to children.
Built by the optimizer when an AnyOf or AllOf group is composed
entirely of case-insensitive string matchers (Contains, StartsWith,
EndsWith, Exact, AhoCorasickSet, plus regexes that carry the
(?i) flag, plus Not / nested AnyOf / AllOf whose every leaf
satisfies these rules).
Invariant: every child must be pre-lowerable. The optimizer’s
is_pre_lowerable validator enforces this; matches_pre_lowered
debug_assert!s on violation.
Why this exists: a mixed AnyOf([Contains, StartsWith, EndsWith])
previously called s.to_lowercase() once per child. Pre-lowering the
haystack a single time and dispatching to a CI-aware match path
eliminates the redundant allocations.
Implementations§
Source§impl CompiledMatcher
impl CompiledMatcher
Sourcepub fn matches(&self, value: &EventValue<'_>, event: &impl Event) -> bool
pub fn matches(&self, value: &EventValue<'_>, event: &impl Event) -> bool
Check if this matcher matches an EventValue from an event.
The event parameter is needed for FieldRef to access other fields.
Source§impl CompiledMatcher
impl CompiledMatcher
Sourcepub fn matches_keyword(&self, event: &impl Event) -> bool
pub fn matches_keyword(&self, event: &impl Event) -> bool
Check if this matcher matches any string value in the event. Used for keyword detection (field-less matching).
Avoids allocating a Vec of all strings and a String per value by
using matches_str with a short-circuiting traversal.
Trait Implementations§
Source§impl Clone for CompiledMatcher
impl Clone for CompiledMatcher
Source§fn clone(&self) -> CompiledMatcher
fn clone(&self) -> CompiledMatcher
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more