---
url: https://docs.ogmabox.com/zh/reference/httpql.md
description: 使用 HTTPQL 和 StreamQL 查询语法筛选 Ogma HTTP 历史、WebSocket 流量、自动化结果及相关视图。
---

# HTTPQL 与 StreamQL {#httpql-and-streamql}

Ogma 使用与 Caido 兼容的查询语言子集，筛选 HTTP 历史、WebSocket 流量、自动化结果及相关视图。

## 语法 {#syntax}

查询由通过 `AND` 和 `OR` 连接的子句组成。

```text
req.host:example.com AND resp.code:200
```

括号用于对表达式分组：

```text
(req.path.cont:"/api/" OR req.path.cont:"/graphql") AND resp.code.gte:400
```

支持注释：

```text
// API errors
req.path.cont:"/api/" AND resp.code.gte:500
```

```text
/* focus on login */
req.path.cont:"login"
```

## 运算符 {#operators}

| 运算符 | 含义 |
| --- | --- |
| `:` | 等于或默认匹配，取决于字段类型 |
| `.eq:` | 等于 |
| `.ne:` | 不等于 |
| `.cont:` | 包含，不区分大小写 |
| `.ncont:` | 不包含，不区分大小写 |
| `.cs.cont:` | 包含，区分大小写 |
| `.cs.ncont:` | 不包含，区分大小写 |
| `.like:` | 类 SQL 模式匹配 |
| `.nlike:` | 类 SQL 模式的不匹配 |
| `.regex:` | 正则表达式匹配 |
| `.nregex:` | 正则表达式不匹配 |
| `.lt:` | 小于 |
| `.lte:` | 小于或等于 |
| `.gt:` | 大于 |
| `.gte:` | 大于或等于 |
| `.exists` | 头部存在；使用 `req.header["Name"].value.exists` 或对应的响应形式 |

## HTTP 示例 {#http-examples}

查找 API 流量：

```text
req.path.cont:"/api/"
```

查找服务器错误：

```text
resp.code.gte:500
```

查找大型响应：

```text
resp.len.gt:100000
```

查找 JSON 响应：

```text
resp.header["content-type"].value.cont:"application/json"
```

查找带有 Cookie 的请求：

```text
req.header["cookie"].value.exists

```

查找经拦截或匹配与替换功能修改的流量：

```text
req.modified.eq:true
```

查找可能的管理路径：

```text
req.path.cont:"/admin" OR req.path.cont:"/manage"
```

查找重放或自动化流量：

```text
source:replay OR source:automate
```

## 流示例 {#stream-examples}

StreamQL 将相同的查询风格应用于 WebSocket 和流视图。

查找包含令牌字段的 WebSocket 消息：

```text
ws.raw.cont:"token"
```

查找从服务器发往客户端的消息：

```text
ws.direction.eq:"To Client"
```

查找类似 JSON 的消息：

```text
ws.raw.cont:"{" AND ws.raw.cont:"}"
```

## 实用的已保存筛选器 {#practical-saved-filters}

| 名称 | 查询 |
| --- | --- |
| API 错误 | `req.path.cont:"/api/" AND resp.code.gte:400` |
| 身份验证端点 | `req.path.cont:"login" OR req.path.cont:"oauth" OR req.path.cont:"session"` |
| JSON 流量 | `resp.header["content-type"].value.cont:"json"` |
| 值得关注的方法 | `req.method:POST OR req.method:PUT OR req.method:PATCH OR req.method:DELETE` |
| 潜在机密 | `resp.body.cont:"api_key" OR resp.body.cont:"secret" OR resp.body.cont:"token"` |

## 限制 {#limits}

为使筛选器行为可预测，Ogma 限制查询复杂度：

* 最大嵌套表达式深度：16。
* 最大子句数量：64。

如果查询过于复杂，请将其拆分为已保存的筛选器，或使用搜索进行更广泛的调查。
