CEL functions and operators

CEL expressions for agent status evaluation support built-in CEL operators and the following function libraries.

Time functions

now()

Returns the current time. Use with last_update to calculate durations or detect stale data.

// True if more than 10 minutes since last heartbeat
now() - last_update > duration('10m')
// True if more than 5 minutes since last heartbeat
now() - last_update > duration('5m')

Math functions

Math functions from the CEL math library are available for numeric calculations.

Commonly used functions

FunctionDescriptionExample
math.greatest(a, b, ...)Returns the greatest value.math.greatest(log_errors, log_warnings)
math.least(a, b, ...)Returns the least value.math.least(agent.metrics_gathered, 1000)

Example

// Warn if either errors or warnings exceed a threshold
math.greatest(log_errors, log_warnings) > 5

String functions

String functions from the CEL strings library are available for string operations. These are useful when checking plugin alias or id fields.

Example

// Check if any input plugin has an alias containing "critical"
inputs.cpu.exists(i, has(i.alias) && i.alias.contains("critical"))

Encoding functions

Encoding functions from the CEL encoder library are available for encoding and decoding values.

Operators

CEL supports standard operators for building expressions.

Comparison operators

OperatorDescriptionExample
==Equalmetrics == 0
!=Not equallog_errors != 0
<Less thanagent.metrics_gathered < 100
<=Less than or equalbuffer_fullness <= 0.5
>Greater thanlog_errors > 10
>=Greater than or equalmetrics >= 1000

Logical operators

OperatorDescriptionExample
&&Logical ANDlog_errors > 0 && metrics == 0
||Logical ORlog_errors > 10 || log_warnings > 50
!Logical NOT!(metrics > 0)

Arithmetic operators

OperatorDescriptionExample
+Additionlog_errors + log_warnings
-Subtractionagent.metrics_gathered - agent.metrics_dropped
*Multiplicationlog_errors * 2
/Divisionagent.metrics_dropped / agent.metrics_gathered
%Modulometrics % 100

Ternary operator

// Conditional expression
log_errors > 10 ? true : false

List operations

FunctionDescriptionExample
exists(var, condition)True if any element matches.inputs.cpu.exists(i, i.errors > 0)
all(var, condition)True if all elements match.outputs.influxdb_v2.all(o, o.errors == 0)
size()Number of elements.inputs.cpu.size() > 0
has()True if a field or key exists.has(inputs.cpu)

Was this page helpful?

Thank you for your feedback!