Operators

An operator decides whether a condition matches its transformed fields. Value operators take value or an operand; set operators take values or a list; numeric and count operators take number. negated inverts operators that support it. See Rule flow for operands and Detectors and patterns for Detect.

Operator Since Description
Equal 1.0.0-alpha4 Matches a value equal to the operand using ordinal, case-sensitive comparison.
StartsWith 1.0.0-alpha4 Matches a value that starts with the operand using ordinal, case-sensitive comparison.
EndsWith 1.0.0-alpha4 Matches a value that ends with the operand using ordinal, case-sensitive comparison.
Contains 1.0.0-alpha4 Matches a value that contains the operand using ordinal, case-sensitive comparison.
PhraseSet 1.0.0-alpha4 Matches a value containing any phrase from values or a list, optionally ignoring case.
Exists 1.0.0-alpha4 Matches when at least one selected field is present.
CountAtLeast 1.0.0-alpha4 Matches when at least the given number of selected fields are present.
NumericGreaterThan 1.0.0-alpha4 Matches a value that parses as a signed 64-bit integer greater than number.
NumericLessThan 1.0.0-alpha4 Matches a value that parses as a signed 64-bit integer less than number.
LengthGreaterThan 1.0.0-alpha4 Matches a value longer than the given number of characters.
LengthLessThan 1.0.0-alpha4 Matches a value shorter than the given number of characters.
SafeRegex 1.0.0-alpha4 Matches a non-backtracking regular expression and captures its named groups.
Malformed 1.0.0-alpha4 Matches a field its parser or a decoding step flagged as malformed. Supports ProtocolAnomaly, RawQuery, JsonScalarValue, FormValue, MultipartTextValue and XmlText; an XmlText marker can guard raw-body fallback rules after malformed XML parsing.
InSet 1.0.0-alpha4 Matches a value that equals an entry of values or a list, optionally ignoring case.
ValidateByteRange 1.0.0-alpha4 Matches when any byte in the value's UTF-8 encoding falls outside the configured byte ranges.
ValidateUtf8 1.0.0-alpha4 Matches a value containing a Unicode replacement character or an unpaired UTF-16 surrogate.
ValidateUriEncoding 1.0.0-alpha4 Matches a value with invalid percent-encoding.
NumericEqual 1.0.0-alpha4 Matches a value that parses as a signed 64-bit integer equal to number.
NumericGreaterOrEqual 1.0.0-alpha4 Matches a value that parses as a signed 64-bit integer greater than or equal to number.
IpIn 1.0.0-alpha4 Matches a value that parses as an IP address, including inet_aton and IPv6 mapped forms, inside a CIDR list.
UriHostIn 1.0.0-alpha4 Matches a URL, under RFC 3986 or WHATWG rules, whose host is in a CIDR list or matches a host pattern; DNS is never resolved.
OffOrigin 1.0.0-alpha4 Matches a parsed URL whose host differs from the request origin and all allowed host patterns; relative URLs use the request origin.
Detect 1.0.0-alpha4 Runs a detector from the same ruleset and reports the matching pattern's reason code or the fingerprint reason.