PageSourceSearch

https://inspektor-gadget.io/assets/js/fc0e3e83.0dd335ed.js

js inspektor-gadget.io collected 2026-10-02 04:01:40 UTC 6,122 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkig_website=self.webpackChunkig_website||[]).push([[11116],{53928:(e,i,r)=>{r.r(i),r.d(i,{assets:()=>o,contentTitle:()=>a,default:()=>h,frontMatter:()=>l,metadata:()=>n,toc:()=>c});const n=JSON.parse('{"id":"spec/operators/filter","title":"Filter","description":"The Filter operator filters events in user space. Since the filtering in user","source":"@site/versioned_docs/version-main/spec/operators/filter.md","sourceDirName":"spec/operators","slug":"/spec/operators/filter","permalink":"/docs/main/spec/operators/filter","draft":false,"unlisted":false,"editUrl":"https://github.com/inspektor-gadget/inspektor-gadget/edit/main/versioned_docs/version-main/spec/operators/filter.md","tags":[],"version":"main","frontMatter":{"title":"Filter"},"sidebar":"mainSidebar","previous":{"title":"Environment Variables","permalink":"/docs/main/spec/operators/env"},"next":{"title":"Formatters","permalink":"/docs/main/spec/operators/formatters"}}');var s=r(74848),t=r(28453);const l={title:"Filter"},a=void 0,o={},c=[{value:"Priority",id:"priority",level:2},{value:"Instance Parameters",id:"instance-parameters",level:2},{value:"filter",id:"filter",level:3},{value:"multiple filters",id:"multiple-filters",level:3}];function d(e){const i={a:"a",admonition:"admonition",code:"code",h2:"h2",h3:"h3",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,t.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsxs)(i.p,{children:["The Filter operator filters events in user space. Since the filtering in user\nspace is slower, it's preferred to use in-ebpf filtering options when possible,\nas provided by other operators like ",(0,s.jsx)(i.a,{href:"/docs/main/spec/operators/localmanager",children:"LocalManager"})," and\n",(0,s.jsx)(i.a,{href:"/docs/main/spec/operators/kubemanager",children:"KubeManager"})," or specific\n",(0,s.jsx)(i.a,{href:"/docs/main/gadget-devel/parameters",children:"parameters"})," provided by each gadget."]}),"\n",(0,s.jsx)(i.h2,{id:"priority",children:"Priority"}),"\n",(0,s.jsx)(i.p,{children:"9000"}),"\n",(0,s.jsx)(i.h2,{id:"instance-parameters",children:"Instance Parameters"}),"\n",(0,s.jsx)(i.h3,{id:"filter",children:"filter"}),"\n",(0,s.jsx)(i.p,{children:"This parameter allows you to filter events based on specific field values\nprovided by the gadget. This is particularly useful for narrowing down the\noutput to entries that meet certain criteria."}),"\n",(0,s.jsx)(i.p,{children:"The filter syntax supports the following operations:"}),"\n",(0,s.jsxs)(i.ul,{children:["\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.code,{children:"field==value"}),": Matches if the content of ",(0,s.jsx)(i.code,{children:"field"})," equals exactly ",(0,s.jsx)(i.code,{children:"value"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.code,{children:"field!=value"}),": Matches if the content of ",(0,s.jsx)(i.code,{children:"field"})," does not equal exactly ",(0,s.jsx)(i.code,{children:"value"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.code,{children:"field>=value"}),": Matches if the content of ",(0,s.jsx)(i.code,{children:"field"})," is greater than or equal to ",(0,s.jsx)(i.code,{children:"value"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.code,{children:"field>value"}),": Matches if the content of ",(0,s.jsx)(i.code,{children:"field"})," is greater than ",(0,s.jsx)(i.code,{children:"value"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.code,{children:"field<=value"}),": Matches if the content of ",(0,s.jsx)(i.code,{children:"field"})," is less than or equal to ",(0,s.jsx)(i.code,{children:"value"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.code,{children:"field<value"}),": Matches if the content of ",(0,s.jsx)(i.code,{children:"field"})," is less than ",(0,s.jsx)(i.code,{children:"value"}),"."]}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.code,{children:"field~value"}),": Matches if the content of ",(0,s.jsx)(i.code,{children:"field"})," matches the regular expression ",(0,s.jsx)(i.code,{children:"value"}),". See ",(0,s.jsx)(i.a,{href:"https://github.com/google/re2/wiki/Syntax",children:"RE2 Syntax"})," for more details."]}),"\n"]}),"\n",(0,s.jsxs)(i.admonition,{type:"info",children:[(0,s.jsxs)(i.p,{children:["It's recommended to wrap the ",(0,s.jsx)(i.strong,{children:"entire"})," filter expression with single quotes when using filters containing special characters to avoid unexpected behavior."]}),(0,s.jsxs)(i.p,{children:[(0,s.jsx)(i.a,{href:"/docs/main/reference/run",children:"CLI"})," example:"]}
1),(0,s.jsx)(i.pre,{children:(0,s.jsx)(i.code,{className:"language-bash",children:"--filter 'proc.comm~^ba.*$'\n"})}),(0,s.jsxs)(i.p,{children:[(0,s.jsx)(i.a,{href:"/docs/main/reference/manifests",children:"Gadget instance manifest"})," example:"]}),(0,s.jsx)(i.pre,{children:(0,s.jsx)(i.code,{className:"language-yaml",children:"operator.filter.filter: 'proc.comm~^ba.*$'\n"})})]}),"\n",(0,s.jsxs)(i.p,{children:["Fully qualified name: ",(0,s.jsx)(i.code,{children:"operator.filter.filter"})]}),"\n",(0,s.jsx)(i.h3,{id:"multiple-filters",children:"multiple filters"}),"\n",(0,s.jsxs)(i.p,{children:["You can specify multiple filters by separating them with a comma. The filter ",(0,s.jsx)(i.code,{children:"field1==value1,field2==value2"})," will match only events where ",(0,s.jsx)(i.code,{children:"field1"})," equals ",(0,s.jsx)(i.code,{children:"value1"})," and ",(0,s.jsx)(i.code,{children:"field2"})," equals ",(0,s.jsx)(i.code,{children:"value2"}),".\nAlso, you can use backslash (",(0,s.jsx)(i.code,{children:"\\"}),") to escape comma in the value."]})]})}function h(e={}){const{wrapper:i}={...(0,t.R)(),...e.components};return i?(0,s.jsx)(i,{...e,children:(0,s.jsx)(d,{...e})}):d(e)}},28453:(e,i,r)=>{r.d(i,{R:()=>l,x:()=>a});var n=r(96540);const s={},t=n.createContext(s);function l(e){const i=n.useContext(t);return n.useMemo((function(){return"function"==typeof e?e(i):{...i,...e}}),[i,e])}function a(e){let i;return i=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:l(e.components),n.createElement(t.Provider,{value:i},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.