Regular Expressions
Click the magnifying glass inside the Find field and choose 'Regular Expression' under 'Compare By' to search with a pattern instead of plain text. 'Regular Expression Help', below that list, opens this page. It works the same in Streams, Layouts and Monitors, and in the Filter field; for the rest of the find bar, see Finding a line.
Which syntax
Patterns use ICU regular expressions, the syntax built into macOS. Most patterns written for Perl, PCRE, Python or JavaScript work as they are. Three things differ from some of those:
- Lookbehind must have a bounded length:
(?<=id=)\d+works, but a*or+inside the lookbehind does not. \d,\wand\bfollow Unicode, so\dalso matches digits from other scripts.- Patterns written for basic
grepput a backslash before groups and repeats (\(,\{,\+). Here those are written without it, and\(means a literal parenthesis.
The full reference is ICU's Regular Expressions guide.
What a pattern is matched against
A pattern is matched against a line's severity, host, process and message, in that order and separated by spaces, and never against the timestamp. A line without those columns, such as one from a plain file, is matched as its message alone. ^ and $ match at the start and end of that text, and . does not match a line break.
Matching ignores case. Start the pattern with (?-i) to make it case-sensitive.
A pattern that is not complete yet, such as (error while you are still typing, finds nothing until it is.
Cheat sheet
.- any character.\d- a digit.\s- white space.\w- a letter, digit or underscore.\b- a word boundary:\bfail\bfindsfailbut notfailed.[abc]- one of the characters.[^abc]- any other character.[0-9a-f]- a range.*- zero or more.+- one or more.?- optional.{3}- exactly three.{2,5}- two to five.*?and+?- as few as possible, so".*?"stops at the first closing quote.error|warn- either alternative.(...)groups, and(?:...)groups without capturing.^and$- the start and end of the text.(?=...)and(?!...)- followed by, or not followed by, without taking it into the match.\.,\(,\[- a literal dot, parenthesis or bracket.\Q...\Etakes everything between the markers literally.
Examples
timeout|refused|reset- any of three words.\b5\d\d\b- a three-digit number starting with 5, such as an HTTP 5xx status.took \d{4,} ?ms- a duration of 1000 ms or more.user=\w+.*denied- a user field withdeniedlater on the line.(?-i)ERROR-ERRORin capitals only.
Tokens in a pattern
Tokens from Insert work inside a pattern, and your own text around them stays a pattern: an IPv4 Address token followed by .*timeout finds an address with timeout later on the line.
See also Finding a line and Filters.