You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 79f6832
Browse filesBrowse the repository at this point in the historyBrowse files
feat(search-events): Teach the logs query agent regex message search
Add logs text-matching guidance to the embedded query-translation agent
prompt so it uses `key://pattern//` regex filters when wildcards cannot
express the request, and add regex few-shot examples for the logs dataset.
Refs LOGS-1014
Co-Authored-By: Claude Code <noreply@anthropic.com>
Copy file name to clipboardExpand all lines: packages/mcp-core/src/tools/support/search-events/config.ts
+38Lines changed: 38 additions & 0 deletions
Original file line number
Diff line number
Diff line change
@@ -122,6 +122,17 @@ REPLAY SEARCH RULES:
122
122
- If the user asks about replays they have viewed, prefer viewed_by_me:true
123
123
- If the user asks about replay users and says "me", use whoami and translate to user.email:<actual email>
124
124
125
+
LOGS TEXT MATCHING (LOGS DATASET ONLY):
126
+
- Plain word or phrase: use wildcards, e.g. message:"*database*". Do NOT use a regex when a substring match is enough
127
+
- Use a regex filter key://pattern// when wildcards cannot express the request: number shapes (\\d+), alternation (a|b), anchoring (^ starts with, $ ends with), character classes ([0-9a-f]), or structured values like IPs, UUIDs, and status codes
128
+
- Example: message://timeout after \\d+ms//
129
+
- Negate with a leading !: !message://job \\d+ completed//
130
+
- There is no list form; use alternation: message://(ConnectionReset|ReadTimeout)Error//
131
+
- NEVER quote a regex: message:"//...//" is a literal string match, not a regex. Spaces and parentheses inside the pattern are fine unquoted
132
+
- Regex uses RE2 syntax (no lookarounds or backreferences), matches anywhere unless anchored, and is case sensitive; prefix the pattern with (?i) to ignore case
133
+
- Patterns are limited to 64 characters (an escape like \\d counts as one). Write \\/\\/ to match a literal //
134
+
- Regex only works on string attributes, and only in the logs dataset; other datasets treat //...// as a literal value
135
+
125
136
MATHEMATICAL QUERY PATTERNS:
126
137
When user asks mathematical questions like "how many X", "total Y used", "sum of Z":
127
138
- Identify the appropriate dataset based on context
0 commit comments