Seq.Syntax
2.0.0-dev-00096
dotnet add package Seq.Syntax --version 2.0.0-dev-00096
NuGet\Install-Package Seq.Syntax -Version 2.0.0-dev-00096
<PackageReference Include="Seq.Syntax" Version="2.0.0-dev-00096" />
<PackageVersion Include="Seq.Syntax" Version="2.0.0-dev-00096" />
<PackageReference Include="Seq.Syntax" />
paket add Seq.Syntax --version 2.0.0-dev-00096
#r "nuget: Seq.Syntax, 2.0.0-dev-00096"
#:package Seq.Syntax@2.0.0-dev-00096
#addin nuget:?package=Seq.Syntax&version=2.0.0-dev-00096&prerelease
#tool nuget:?package=Seq.Syntax&version=2.0.0-dev-00096&prerelease
Seq Syntax
This repository implements Seq-style expressions and the Seq template language over structured event data.
Expressions and templates evaluate against event JSON documents in Seq's emission schema — the
format delivered to Seq apps and API consumers — represented as System.Text.Json.Nodes.JsonObject:
var eventJson = JsonNode.Parse(json)!.AsObject();
var expr = SeqExpression.Compile("@Level = 'Warning' and Contains(@Message, 'coffee')");
if (expr(eventJson).IsTrue()) { /* ... */ }
var template = new ExpressionTemplate("[{@Timestamp:HH:mm:ss} {@Level:u3}] {@Message}");
template.Format(eventJson, Console.Out);
Keyword properties (@Timestamp, @Level, @Message, …) provide typed views over the
document's @t, @l, @mt/@m fields and friends; any other @ identifier reads the
correspondingly-named document member verbatim.
Migrating from 1.x: version 2.0 removed the Serilog dependency and is a breaking change —
SerilogExpressionbecameSeqExpression,LogEventinputs becameJsonObject, and@t,@l,@m, and other short@names became plain JSON reads.
Error in {Environment}!
Here, Environment is an event property, producing a message subject like Error in Production!.
Basic syntax
Templates support:
- Most built-in Seq event properties, including
@Level,@Message, and@Exception, - First-class properties of events and alerts, like
Environmentin the example above, - Most Seq scalar functions, such as
ToIsoString(),Coalesce(),Substring(),IndexOf(), and so on, - Seq operators such as
=,<>,<,>,like,in,is null, - Constant numbers
123.4, strings'abc', Booleantrueandfalse, andnull, - Arrays delimited with brackets
[]and zero-based indexing, - Object literals using braces
{}that support string-based indexing, - Most other Seq expression language features.
Literal braces in templated text fields can be escaped by doubling, {{ and }}.
Formatting of dates and numbers can be achieved using .NET format strings following a colon, e.g.:
Completed in {Elapsed:0.00} ms
Conditionals and repetition
To conditionally include text, use {#if expr}:
{#if Count = 0}
Nothing here
{#else if Count = 1}
Only one
{#else}
Found {Count} items
{#end}
The else/else if blocks are optional.
To iterate over array elements or object properties use {#each e in expr} or {#each k, v in expr}:
{#each name, value in @Properties}
{name} is {value}
{#delimit}
---
{#else}
No properties
{#end}
The delimit and else blocks are optional.
ANSI terminal output
Pass one of the built-in themes (Code, Grayscale, Literate, or Sixteen) to color
terminal output:
var template = new ExpressionTemplate(
"[{@Timestamp:HH:mm:ss} {@Level:u3}] {@Message}\n{@Exception}",
theme: TemplateTheme.Code);
Themes can be customized by overriding the styles of a base theme:
var custom = new AnsiTheme((AnsiTheme)TemplateTheme.Literate, new Dictionary<TemplateThemeStyle, string>
{
[TemplateThemeStyle.LevelInformation] = "\x1b[38;5;34m",
});
Escaping text inserted into HTML message bodies
TemplateOutputEscaper.Html escapes event-derived values automatically, so they can be safely
inserted into HTML attributes and element bodies (excluding script and style contexts, in which
no safe escaping is possible).
var template = new ExpressionTemplate(
"<p>{@Message}</p>",
escaper: TemplateOutputEscaper.Html);
Where an event property is known to contain trusted, well-formed HTML, {unsafe(Markup)}
substitutes it without escaping.
Acknowledgements
This project is based on code from Serilog and Serilog.Expressions.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- Superpower (>= 3.2.1)
NuGet packages (10)
Showing the top 5 NuGet packages that depend on Seq.Syntax:
| Package | Downloads |
|---|---|
|
Seq.Input.HealthCheck
Seq Health Check: periodically GET an HTTP resource and publish response metrics to Seq. |
|
|
Seq.App.HttpRequest
Send events and notifications from Seq to a remote HTTP/REST/WebHook endpoint. |
|
|
Seq.Mail
Shared infrastructure for Seq apps that integrate with email and similar messaging services. |
|
|
Seq.App.AzureSecretCheck
This plug-in checks the secrets and certificates of each of the apps specified and returns the days till expiration of each item. |
|
|
Seq.App.Relay
A simple HTTP/JSON forwarder that preserves all event metadata. |
GitHub repositories (1)
Showing the top 1 popular GitHub repositories that depend on Seq.Syntax:
| Repository | Stars |
|---|---|
|
datalust/seqcli
The Seq command-line client. Administer, log, ingest, search, from any OS.
|
| Version | Downloads | Last Updated |
|---|---|---|
| 2.0.0-dev-00096 | 0 | 8/31/2026 |
| 2.0.0-dev-00095 | 0 | 8/31/2026 |
| 1.2.0 | 205 | 8/6/2026 |
| 1.2.0-dev-00109 | 190 | 8/17/2026 |
| 1.1.2-dev-00106 | 193 | 8/6/2026 |
| 1.1.2-dev-00105 | 208 | 8/6/2026 |
| 1.1.2-dev-00102 | 193 | 8/5/2026 |
| 1.1.1 | 3,716 | 3/10/2026 |
| 1.1.1-dev-00098 | 213 | 3/10/2026 |
| 1.1.1-dev-00097 | 224 | 3/10/2026 |
| 1.1.0 | 2,048 | 10/1/2025 |
| 1.1.0-dev-00093 | 324 | 10/1/2025 |
| 1.1.0-dev-00092 | 399 | 10/1/2025 |
| 1.1.0-dev-00091 | 321 | 10/1/2025 |
| 1.0.1-dev-00079 | 323 | 2/28/2025 |
| 1.0.1-dev-00077 | 387 | 6/19/2024 |
| 1.0.1-dev-00075 | 587 | 5/17/2024 |
| 1.0.1-dev-00072 | 485 | 4/30/2024 |
| 1.0.1-dev-00064 | 363 | 1/2/2024 |
| 1.0.0 | 21,338 | 1/2/2024 |