Skip to content

Commit 79f6832

Browse files
feat(search-events): Teach the logs query agent regex message search
Add logs text-matching guidance to the embedded query-translation agent prompt so it uses `key://pattern//` regex filters when wildcards cannot express the request, and add regex few-shot examples for the logs dataset. Refs LOGS-1014 Co-Authored-By: Claude Code <noreply@anthropic.com>
1 parent 367ece8 commit 79f6832

2 files changed

Lines changed: 39 additions & 0 deletions

File tree

‎docs/contributing/search-events-api-patterns.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -114,6 +114,7 @@ https://us.sentry.io/api/0/organizations/sentry/events/?dataset=spans&field=ai.m
114114
- Does NOT support timestamp filters in query (use `statsPeriod` instead)
115115
- Severity levels: fatal, error, warning, info, debug, trace
116116
- Common aggregate functions: `count()`, `epm()`
117+
- Regex filters on string attributes: `message://timeout after \d+ms//` (RE2, unquoted, max 64 characters); prefer wildcards for plain substrings
117118

118119
#### Metrics Dataset
119120
- Represents newer span metrics, including counters, gauges, and distributions

‎packages/mcp-core/src/tools/support/search-events/config.ts‎

Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -122,6 +122,17 @@ REPLAY SEARCH RULES:
122122
- If the user asks about replays they have viewed, prefer viewed_by_me:true
123123
- If the user asks about replay users and says "me", use whoami and translate to user.email:<actual email>
124124
125+
LOGS TEXT MATCHING (LOGS DATASET ONLY):
126+
- Plain word or phrase: use wildcards, e.g. message:"*database*". Do NOT use a regex when a substring match is enough
127+
- Use a regex filter key://pattern// when wildcards cannot express the request: number shapes (\\d+), alternation (a|b), anchoring (^ starts with, $ ends with), character classes ([0-9a-f]), or structured values like IPs, UUIDs, and status codes
128+
- Example: message://timeout after \\d+ms//
129+
- Negate with a leading !: !message://job \\d+ completed//
130+
- There is no list form; use alternation: message://(ConnectionReset|ReadTimeout)Error//
131+
- NEVER quote a regex: message:"//...//" is a literal string match, not a regex. Spaces and parentheses inside the pattern are fine unquoted
132+
- Regex uses RE2 syntax (no lookarounds or backreferences), matches anywhere unless anchored, and is case sensitive; prefix the pattern with (?i) to ignore case
133+
- Patterns are limited to 64 characters (an escape like \\d counts as one). Write \\/\\/ to match a literal //
134+
- Regex only works on string attributes, and only in the logs dataset; other datasets treat //...// as a literal value
135+
125136
MATHEMATICAL QUERY PATTERNS:
126137
When user asks mathematical questions like "how many X", "total Y used", "sum of Z":
127138
- Identify the appropriate dataset based on context
@@ -720,6 +731,33 @@ export const DATASET_EXAMPLES: Record<
720731
sort: "-timestamp",
721732
},
722733
},
734+
{
735+
description:
736+
"logs whose message reports a retry count like 'retry 3 of 5'",
737+
output: {
738+
query: "message://retry \\d+ of \\d+//",
739+
fields: ["timestamp", "message", "severity", "trace"],
740+
sort: "-timestamp",
741+
},
742+
},
743+
{
744+
description:
745+
"error logs whose message starts with ConnectionReset or ReadTimeout",
746+
output: {
747+
query: "severity:error AND message://^(ConnectionReset|ReadTimeout)//",
748+
fields: ["timestamp", "message", "severity", "trace"],
749+
sort: "-timestamp",
750+
},
751+
},
752+
{
753+
description:
754+
"logs excluding cache hit messages like 'cache hit for key user:42'",
755+
output: {
756+
query: "!message://^cache hit for key \\S+//",
757+
fields: ["timestamp", "message", "severity", "trace"],
758+
sort: "-timestamp",
759+
},
760+
},
723761
],
724762
tracemetrics: [
725763
{

0 commit comments

Comments
 (0)