Skip to content

Expressions (Expr)

Logstrm uses Expr-compatible expressions for pipeline matching and route conditions. Expressions are compiled while loading configuration, so syntax errors fail early instead of appearing for the first time under production traffic.

Common operators

match: 'category == "FrontDoorAccessLog" OR category == "FrontDoorWebApplicationFirewallLog"'
condition: 'http_status_code >= 400'
condition: 'action == "Block" AND http_status_code == 403'

Supported patterns in the shipped configuration include equality, numeric comparisons, boolean AND/OR, parentheses and the literal true.

Field behavior

Fields are resolved from the event map after transformation. If a route depends on a renamed field, use the destination name (http_status_code, not httpStatusCode). Keep type assumptions explicit: a numeric comparison requires a numeric event value.

Testing expressions

  1. Create a fixture containing the fields and types expected by the expression.
  2. Load the configuration before deploying it.
  3. Check route counters and archive output with a representative event.
  4. Include negative cases: a benign status, a non-blocking WAF action and a missing optional field.

Expressions are a routing tool, not a general-purpose scripting escape hatch. Keep business logic readable and put irreversible data reduction in reviewed transformation rules.