Compound advanced policy expressions
http.req.hostname.eq("mycompany.com") && http.req.method.eq(post)
http.req.url.length + http.req.cookie.length \<= 500
http.req.url.length + http.req.cookie.length \<= 500 && http.req.header.contains("some text")
Booleans in compound expressions
-
&&This operator is a logical AND. For the expression to evaluate to TRUE, all components must evaluate to TRUE.Example:http.req.url.hostname.eq("myHost") && http.req.header("myHeader").exists
-
\|\|This operator is a logical OR. If any component of the expression evaluates to TRUE, the entire expression is TRUE.
-
!This operator does a logical NOT on the expression.
-
IFThis operator does a logical IF on the boolean expression. If the boolean expression is true, the first expression (expr1) is evaluated. If the boolean expression is false, the first expression (expr1) is skipped, and the second expression (expr2) is evaluated. The third expression (expr3) is further processed based on the result of the IF function.IF operator syntax:
<boolean expr>.IF(<expr1>, <expr2>).<expr3>Example1: Client IP source in subnetCLIENT.IP.SRC.IN_SUBNET(10.0.0.0/8).IF(HTTP.REQ.HEADER("PERSIST-VAL"), HTTP.REQ.HEADER("ABCD"))This expression checks if the source IP address of the client is within the 10.0.0.0/8 subnet. If True, it uses a conditional IF logic to select a persistence value based on the presence of a specific HTTP request header. If False, it uses the value of the "ABCD" header.Example2: Content length-based data checkHTTP.REQ.HEADER("Content-Length").EXISTS.IF(HTTP.REQ.BODY(HTTP.REQ.CONTENT_LENGTH), HTTP.REQ.BODY(100000)).CONTAINS("mydata")This expression checks if the HTTP request is based on content length. If True, the data is retrieved according to the value specified in the content-length header. If False, the first 100,000 bytes of the request body are inspected.
Parentheses in compound expressions
http.req.url.contains("myCompany.com") || (http.req.url.hostname.eq("myHost") && http.req.header("myHeader").exists)
(http.req.header("Content-Type").exists && http.req.header("Content-Type").eq("text/html")) || (http.req.header("Transfer-Encoding").exists || http.req.header("Content-Length").exists)
Compound operations for strings
| Operations that produce a string value | Description |
|---|---|
| str + str | Concatenates the value of the expression on the left of the operator with the value on the right. Example: http.req.hostname + http.req.url.protocol |
| str + num | Concatenates the value of the expression on the left of the operator with a numeric value on the right. Example: http.req.hostname + http.req.url.content_length |
| num + str | Concatenates the numeric value of the expression on the left side of the operator with a string value on the right. Example: http.req.url.content_length + http.req.url.hostname |
| str + ip | Concatenates the string value of the expression on the left side of the operator with an IP address value on the right. Example: http.req.hostname + 10.00.000.00 |
| IP + str | Concatenates the IP address value of the expression on the left of the operator with a string value on the right. Example: client.ip.dst + http.req.url.hostname |
| str1 ALT str2 | Uses string2 if the evaluation of string1 results in an undef exception or the result is a null string. Otherwise uses string1 and never evaluates string2. Example: http.req.hostname alt client.ip.src |
| Operations on strings that produce a result of TRUE or FALSE | Description |
|---|---|
| str == str | Evaluates whether the strings on either side of the operator are the same. Example: http.req.header("myheader") == http.res.header("myheader") |
| str <= str | Evaluates whether the string on the left side of the operator is the same as the string on the right, or precedes it alphabetically. |
| str >= str | Evaluates whether the string on the left side of the operator is the same as the string on the right, or follows it alphabetically. |
| str < str | Evaluates whether the string on the left side of the operator precedes the string on the right alphabetically. |
| str > str | Evaluates whether the string on the left side of the operator follows the string on the right alphabetically. |
| str !!= str | Evaluates whether the strings on either side of the operator are different. |
| Logical operations on strings | Description |
|---|---|
| bool && bool | This operator is a logical AND. When evaluating the components of the compound expression, all components that are joined by the AND must evaluate to TRUE. Example: http.req.method.eq(GET) && http.req.url.query.contains("viewReport && my_pagelabel") |
| bool || bool | This operator is a logical OR. When evaluating the components of the compound expression, if any component of the expression belonging to OR evaluates to TRUE, the entire expression is TRUE. Example: http.req.url.contains(".js") || http.res.header.("Content-Type"). Contains("javascript") |
| bool | Performs a logical NOT on the expression. |
Compound operations for numbers
http.req.header.length + http.req.url.length
| Arithmetic operations on numbers | Description |
|---|---|
| num + num | Add the value of the expression on the left to the value on the right. Example: http.req.content_length + http.req.url.length |
| num – num | Subtract the value of the expression on the right from the value on the left. |
| num*num | Multiply the value of the expression on the left of the operator with the value of the expression on the right. Example: client.interface.rxthroughput* 9 |
| num / num | Divide the value of the expression on the left of the operator by the value of the expression on the right. |
| num % num | Calculate the modulo, or the numeric remainder on a division of the value of the expression on the left of the operator by the value of the expression on the right. For example, the values "15 mod 4" equals 3, and "12 mod 4" equals 0. |
| ~number | Returns a number after applying a bitwise logical negation of the number. The following example assumes that numeric.expression returns 12 (binary 1100): ~numeric.expression. The result of applying the ~ operator is -11 (a binary 1110011, 32 bits total with all ones to the left). Note that all returned values of less than 32 bits before applying the operator implicitly have zeros to the left to make them 32 bits wide. |
| number \^ number | Compares two bit patterns of equal length and performs an XOR operation on each pair of corresponding bits in each number argument, returning 1 if the bits are different, and 0 if they are the same. Returns a number after applying a bitwise XOR to the integer argument and the current number value. If the values in the bitwise comparison are the same, the returned value is a 0. The following example assumes that numeric.expression1 returns 12 (binary 1100) and numeric.expression2 returns 10 (binary 1010): numeric.expression1 \^ numeric.expression2The result of applying the \^ operator to the entire expression is 6 (binary 0110). Note that all returned values of less than 32 bits before applying the operator implicitly have zeros to the left to make them 32 bits wide. |
| number | number | Returns a number after applying a bitwise OR to the number values. If either value in the bitwise comparison is a 1, the returned value is a 1. The following example assumes that numeric.expression1 returns 12 (binary 1100) and numeric.expression2 returns 10 (binary 1010): numeric.expression1 | numeric.expression2 The result of applying the | operator to the entire expression is 14 (binary 1110). Note that all returned values of less than 32 bits before applying the operator implicitly have zeros to the left to make them 32 bits wide. |
| number & number | Compares two bit patterns of equal length and performs a bitwise AND operation on each pair of corresponding bits, returning 1 if both of the bits contains a value of 1, and 0 if either bits are 0. The following example assumes that numeric.expression1 returns 12 (binary 1100) and numeric.expression2 returns 10 (binary 1010): numeric.expression1 & numeric.expression2 The whole expression evaluates to 8 (binary 1000). Note that all returned values of less than 32 bits before applying the operator implicitly have zeros to the left to make them 32 bits wide. |
| num << num | Returns a number after a bitwise left shift of the number value by the right-side number argument number of bits. Note that the number of bits shifted is integer modulo 32. The following example assumes that numeric.expression1 returns 12 (binary 1100) and numeric.expression2 returns 3: numeric.expression1 << numeric.expression2 The result of applying the LSHIFT operator is 96 (a binary 1100000).Note that all returned values of less than 32 bits before applying the operator implicitly have zeros to the left to make them 32 bits wide. |
| num >> num | Returns a number after a bitwise right shift of the number value by the integer argument number of bits. Note that the number of bits shifted is integer modulo 32. The following example assumes that numeric.expression1 returns 12 (binary 1100) and numeric.expression2 returns 3: numeric.expression1 >> numeric.expression2 The result of applying the RSHIFT operator is 1 (a binary 0001). Note that all returned values of less than 32 bits before applying the operator implicitly have zeros to the left to make them 32 bits wide. |
| Numeric operators that produce a result of TRUE or FALSE | Description |
|---|---|
| num == num | Determine if the value of the expression on the left of the operator is equal to the value of the expression on the right. |
| num!= num | Determine if the value of the expression on the left of the operator is not equal to the value of the expression on the right. |
| num > num | Determine if the value of the expression on the left of the operator is greater than the value of the expression on the right. |
| num < num | Determine if the value of the expression on the left of the operator is less than the value of the expression on the right. |
| num >= num | Determine if the value of the expression on the left of the operator is greater than or equal to the value of the expression on the right. |
| num <= num | Determine if the value of the expression on the left of the operator is less than or equal to the value of the expression on the right |
Functions for data types in the policy infrastructure
-
Integer (32 bits)
-
Unsigned long (64 bits)
-
Double (64 bits)
Arithmetic Operators, Logical Operators, and Type Promotion
-
+, -, *, and /
-
%, ~, \^, &, |, \<\<, and \>\> (do not apply to double)
-
\==,!=, \>, \<, \>=, and \<=
-
Double
-
Unsigned long
-
Integer