diff --git a/docs/contributing/search-events-api-patterns.md b/docs/contributing/search-events-api-patterns.md index b6299c234..5fe627927 100644 --- a/docs/contributing/search-events-api-patterns.md +++ b/docs/contributing/search-events-api-patterns.md @@ -114,6 +114,7 @@ https://us.sentry.io/api/0/organizations/sentry/events/?dataset=spans&field=ai.m - Does NOT support timestamp filters in query (use `statsPeriod` instead) - Severity levels: fatal, error, warning, info, debug, trace - Common aggregate functions: `count()`, `epm()` +- Regex filters on string attributes: `message://timeout after \d+ms//` (RE2, unquoted, max 64 characters); prefer wildcards for plain substrings, prefixes, and suffixes #### Metrics Dataset - Represents newer span metrics, including counters, gauges, and distributions diff --git a/packages/mcp-core/src/tools/support/search-events/config.ts b/packages/mcp-core/src/tools/support/search-events/config.ts index 27d4a42a4..3c344263c 100644 --- a/packages/mcp-core/src/tools/support/search-events/config.ts +++ b/packages/mcp-core/src/tools/support/search-events/config.ts @@ -122,6 +122,21 @@ REPLAY SEARCH RULES: - If the user asks about replays they have viewed, prefer viewed_by_me:true - If the user asks about replay users and says "me", use whoami and translate to user.email: +LOGS TEXT MATCHING (LOGS DATASET ONLY): +- Plain word, phrase, prefix, or suffix: use wildcards. message:"*database*" contains, message:"database*" starts with, message:"*database" ends with. Do NOT use a regex when a wildcard is enough +- Any of several plain words or phrases: use a wildcard list, e.g. message:["*ConnectionReset*","*ReadTimeout*"] +- Use a regex filter key://pattern// when wildcards cannot express the request: number shapes (\\d+), character classes ([0-9a-f]), structured values like IPs, UUIDs, and status codes, or ignoring case (wildcards are case sensitive). Use alternation (a|b) and anchors (^ or $) only alongside one of these + - Example: message://request took \\d+ms// + - Negate with a leading !: !message://worker \\d+ ready// + - There is no regex list form (key:[//a//,//b//] is a literal list); put alternatives inside one pattern: message://(upload|download) of \\d+ bytes failed// + - For an exact set of values, keep the list: severity:[error,fatal], not severity://error|fatal// +- Regex on message is for text inside the message. When the user asks about a value that has its own attribute (e.g. response status), filter that attribute instead +- NEVER quote a regex: message:"//...//" is a literal string match, not a regex +- The pattern ends at the first // followed by a space, ) or the end of the query. Spaces, parentheses, and a // followed by anything else (https?://host) are fine unquoted; write \\/\\/ for a literal // followed by a space or ) +- Regex uses RE2 syntax (no lookarounds or backreferences), matches anywhere unless anchored, and is case sensitive; prefix the pattern with (?i) to ignore case +- Patterns are limited to 64 characters (an escape like \\d counts as one), so keep them short: leave out \\b unless the request needs it, and match either case with (?i)[0-9a-f] rather than [0-9a-fA-F] +- Regex only works on string attributes in the logs dataset. NEVER write key://pattern// for errors, spans, metrics, or any other dataset: they match //...// literally and return nothing. Approximate the shape with wildcards there, e.g. message:"*retry*failed*" + MATHEMATICAL QUERY PATTERNS: When user asks mathematical questions like "how many X", "total Y used", "sum of Z": - Identify the appropriate dataset based on context @@ -720,6 +735,33 @@ export const DATASET_EXAMPLES: Record< sort: "-timestamp", }, }, + { + description: + "logs whose message reports a retry count like 'retry 3 of 5'", + output: { + query: "message://retry \\d+ of \\d+//", + fields: ["timestamp", "message", "severity", "trace"], + sort: "-timestamp", + }, + }, + { + description: + "error logs whose message contains a hex error code like 'err=0x8007000e'", + output: { + query: "severity:error AND message://err=0x[0-9a-f]+//", + fields: ["timestamp", "message", "severity", "trace"], + sort: "-timestamp", + }, + }, + { + description: + "logs excluding heartbeat messages like 'heartbeat seq=1042'", + output: { + query: "!message://^heartbeat seq=\\d+$//", + fields: ["timestamp", "message", "severity", "trace"], + sort: "-timestamp", + }, + }, ], tracemetrics: [ {