Skip to main content

Stricter Validation for Boolean Expressions in Search Queries (Search)

Sumo Logic will enforce stricter validation for AND/OR Boolean expressions in search queries. Previously, Sumo Logic relied on proper user queries. The system accepted user queries with incomplete Boolean syntax, such as:

| where user_username = "root" and success
| where ip matches "192.*" or "1.*"

In the above examples, success and 1.* are not valid Boolean expressions on their own. These queries produced unexpected results because the system silently skipped the invalid expressions during evaluation. However, the user’s incomplete entry was not disclosed as faulty.

What's changing​

Sumo Logic now proactively validates that both sides of an AND or OR operator are valid Boolean expressions. Queries with invalid Boolean syntax will return a validation error when you create or update content such as monitors, scheduled searches, and scheduled views. This helps you identify and correct incomplete queries before saving them.

note

Existing saved content will continue to execute as before. This change affects only new or edited content. Review whether this change affects your operations, and whether you need to edit and re-run existing saved content.

To fix affected queries, ensure each operand in an AND/OR expression is a complete Boolean expression. For example:

| where user_username = "root" and success = true
| where ip matches "192.*" or ip matches "1.*"

For more information, contact your account team.

Status
Legal
Privacy Statement
Terms of Use
CA Privacy Notice

Copyright © 2026 by Sumo Logic, Inc.