Skip to content
Draft
1 change: 1 addition & 0 deletions docs/contributing/search-events-api-patterns.md
Original file line number Diff line number Diff line change
Expand Up @@ -114,6 +114,7 @@ https://us.sentry.io/api/0/organizations/sentry/events/?dataset=spans&field=ai.m
- Does NOT support timestamp filters in query (use `statsPeriod` instead)
- Severity levels: fatal, error, warning, info, debug, trace
- Common aggregate functions: `count()`, `epm()`
- Regex filters on string attributes: `message://timeout after \d+ms//` (RE2, unquoted, max 64 characters); prefer wildcards for plain substrings, prefixes, and suffixes

#### Metrics Dataset
- Represents newer span metrics, including counters, gauges, and distributions
Expand Down
42 changes: 42 additions & 0 deletions packages/mcp-core/src/tools/support/search-events/config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -122,6 +122,21 @@ REPLAY SEARCH RULES:
- If the user asks about replays they have viewed, prefer viewed_by_me:true
- If the user asks about replay users and says "me", use whoami and translate to user.email:<actual email>

LOGS TEXT MATCHING (LOGS DATASET ONLY):
- Plain word, phrase, prefix, or suffix: use wildcards. message:"*database*" contains, message:"database*" starts with, message:"*database" ends with. Do NOT use a regex when a wildcard is enough
- Any of several plain words or phrases: use a wildcard list, e.g. message:["*ConnectionReset*","*ReadTimeout*"]
- Use a regex filter key://pattern// when wildcards cannot express the request: number shapes (\\d+), character classes ([0-9a-f]), structured values like IPs, UUIDs, and status codes, or ignoring case (wildcards are case sensitive). Use alternation (a|b) and anchors (^ or $) only alongside one of these
- Example: message://request took \\d+ms//
- Negate with a leading !: !message://worker \\d+ ready//
- There is no regex list form (key:[//a//,//b//] is a literal list); put alternatives inside one pattern: message://(upload|download) of \\d+ bytes failed//
- For an exact set of values, keep the list: severity:[error,fatal], not severity://error|fatal//
- Regex on message is for text inside the message. When the user asks about a value that has its own attribute (e.g. response status), filter that attribute instead
- NEVER quote a regex: message:"//...//" is a literal string match, not a regex
- The pattern ends at the first // followed by a space, ) or the end of the query. Spaces, parentheses, and a // followed by anything else (https?://host) are fine unquoted; write \\/\\/ for a literal // followed by a space or )
- Regex uses RE2 syntax (no lookarounds or backreferences), matches anywhere unless anchored, and is case sensitive; prefix the pattern with (?i) to ignore case
- Patterns are limited to 64 characters (an escape like \\d counts as one), so keep them short: leave out \\b unless the request needs it, and match either case with (?i)[0-9a-f] rather than [0-9a-fA-F]
- Regex only works on string attributes in the logs dataset. NEVER write key://pattern// for errors, spans, metrics, or any other dataset: they match //...// literally and return nothing. Approximate the shape with wildcards there, e.g. message:"*retry*failed*"

MATHEMATICAL QUERY PATTERNS:
When user asks mathematical questions like "how many X", "total Y used", "sum of Z":
- Identify the appropriate dataset based on context
Expand Down Expand Up @@ -720,6 +735,33 @@ export const DATASET_EXAMPLES: Record<
sort: "-timestamp",
},
},
{
description:
"logs whose message reports a retry count like 'retry 3 of 5'",
output: {
query: "message://retry \\d+ of \\d+//",
fields: ["timestamp", "message", "severity", "trace"],
sort: "-timestamp",
},
},
{
description:
"error logs whose message contains a hex error code like 'err=0x8007000e'",
output: {
query: "severity:error AND message://err=0x[0-9a-f]+//",
fields: ["timestamp", "message", "severity", "trace"],
sort: "-timestamp",
},
},
{
description:
"logs excluding heartbeat messages like 'heartbeat seq=1042'",
output: {
query: "!message://^heartbeat seq=\\d+$//",
fields: ["timestamp", "message", "severity", "trace"],
sort: "-timestamp",
},
},
],
tracemetrics: [
{
Expand Down
Loading