{
    "mode": "man",
    "parameter": "ausearch-expression",
    "section": "5",
    "url": "https://www.chedong.com/phpMan.php/man/ausearch-expression/5/json",
    "generated": "2026-10-06T07:26:45Z",
    "sections": {
        "NAME": {
            "content": "ausearch-expression - audit search expression format\n\n",
            "subsections": []
        },
        "OVERVIEW": {
            "content": "This  man  page  describes  the  format of \"ausearch expressions\".  Parsing and evaluation of\nthese expressions is provided by libauparse and is common to applications that use  this  li‐\nbrary.\n\n",
            "subsections": []
        },
        "LEXICAL STRUCTURE": {
            "content": "White  space  (ASCII space, tab and new-line characters) between tokens is ignored.  The fol‐\nlowing tokens are recognized:\n\n\nPunctuation\n( ) \\\n\n\nLogical operators\n! && ||\n\n\nComparison operators\n< <= == > >= !== i= i!= r= r!=\n\n\nUnquoted strings\nAny non-empty sequence of ASCII letters, digits, and the  symbol.\n\n\nQuoted strings\nA sequence of characters surrounded by the \" quotes.  The \\ character starts an escape\nsequence.  The only defined escape sequences are \\\\ and \\\".  The  semantics  of  other\nescape sequences is undefined.\n\n\nRegexps\nA  sequence  of  characters surrounded by the / characters.  The \\ character starts an\nescape sequence.  The only defined escape sequences are \\\\ and \\/.  The  semantics  of\nother escape sequences is undefined.\n\n\nAnywhere  an  unquoted string is valid, a quoted string is valid as well, and vice versa.  In\nparticular, field names may be specified using quoted strings, and field values may be speci‐\nfied using unquoted strings.\n\n",
            "subsections": []
        },
        "EXPRESSION SYNTAX": {
            "content": "The primary expression has one of the following forms:\n\nfield comparison-operator value\n\n\\regexp string-or-regexp\n\nfield is either a string, which specifies the first field with that name within  the  current\naudit record, or the \\ escape character followed by a string, which specifies a virtual field\nwith the specified name (virtual fields are defined in a later section).\n\nfield is a string.  operator specifies the comparison to perform\n\n\nr= r!= Get  the \"raw\" string of field, and compare it to value.  For fields in audit records,\nthe \"raw\" string is the exact string stored in the audit record (with all escaping and\nunprintable character encoding left alone); applications can read the \"raw\" string us‐\ning auparsegetfieldstr(3).  Each virtual field may define a \"raw\" string.  If field\nis not present or does not define a \"raw\" string, the  result  of  the  comparison  is\nfalse (regardless of the operator).\n\n\ni= i!= Get  the  \"interpreted\" string of field, and compare it to value.  For fields in audit\nrecords, the \"interpreted\" string is an \"user-readable\" interpretation  of  the  field\nvalue;   applications   can   read   the  \"interpreted\"  string  using  auparseinter‐\npretfield(3).  Each virtual field may define an \"interpreted\" string.   If  field  is\nnot  present  or does not define an \"interpreted\" string, the result of the comparison\nis false (regardless of the operator).\n\n",
            "subsections": [
                {
                    "name": "< <= == > >= !==",
                    "content": "Evaluate the \"value\" of field, and compare it to value.  A \"value\" may be defined  for\nany  field  or virtual field, but no \"value\" is currently defined for any audit record\nfield.  The rules of parsing value for comparing it with the \"value\" of field are spe‐\ncific for each field.  If field is not present, the result of the comparison is  false\n(regardless  of  the  operator).   If field does not define a \"value\", an error is re‐\nported when parsing the expression.\n\nIn the special case of \\regexp regexp-or-string, the current  audit  record  is  taken  as  a\nstring (without interpreting field values), and matched against regexp-or-string.  regexp-or-\nstring is an extended regular expression, using a string or regexp token (in other words, de‐\nlimited by \" or /).\n\nIf  E1 and E2 are valid expressions, then !  E1, E1 && E2, and E1 || E2 are valid expressions\nas well, with the usual C semantics and evaluation priorities.  Note that !  field  op  value\nis interpreted as !(field op value), not as (!field) op value.\n\n"
                }
            ]
        },
        "VIRTUAL FIELDS": {
            "content": "The following virtual fields are defined:\n\n",
            "subsections": [
                {
                    "name": "\\timestamp",
                    "content": "The value is the timestamp of the current event.  value must be formatted as:\n\nts:seconds.milli\n\nwhere  seconds  and  milli are decimal numbers specifying the seconds and milliseconds\npart of the timestamp, respectively.\n\n"
                },
                {
                    "name": "\\timestamp_ex",
                    "content": "This is similar to \\timestamp but also includes the event's serial number.  value must\nbe formatted as:\n\nts:seconds.milli:serial\n\nwhere serial is a decimal number specifying the event's serial number.\n\n"
                },
                {
                    "name": "\\record_type",
                    "content": "The value is the type of the current record.  value is either the record type name, or\na decimal number specifying the type.\n\n"
                }
            ]
        },
        "SEMANTICS": {
            "content": "The expression as a whole applies to a single record.  The expression is true for a specified\nevent if it is true for any record associated with the event.\n\n",
            "subsections": []
        },
        "EXAMPLES": {
            "content": "As a demonstration of the semantics of handling missing fields, the following  expression  is\ntrue if field is present:\n\n(field r= \"\") || (field r!= \"\")\n\nand the same expression surrounded by !( and ) is true if field is not present.\n\n",
            "subsections": []
        },
        "FUTURE DIRECTIONS": {
            "content": "New escape sequences for quoted strings may be defined.\n\nFor  currently defined virtual fields that do not define a \"raw\" or \"interpreted\" string, the\ndefinition may be added.  Therefore, don't rely on the fact that comparing the \"raw\" or  \"in‐\nterpreted\" string of the field with any value is false.\n\nNew formats of value constants for the \\timestamp virtual field may be added.\n\n",
            "subsections": []
        },
        "AUTHOR": {
            "content": "Miloslav Trmac\n\nRed Hat                                       Feb 2008                        AUSEARCH-EXPRESSION(5)",
            "subsections": []
        }
    },
    "summary": "ausearch-expression - audit search expression format",
    "flags": [],
    "examples": [
        "As a demonstration of the semantics of handling missing fields, the following  expression  is",
        "true if field is present:",
        "(field r= \"\") || (field r!= \"\")",
        "and the same expression surrounded by !( and ) is true if field is not present."
    ],
    "see_also": []
}