2026-04-21 10:50:09 +02:00
|
|
|
/*
|
|
|
|
|
Copyright © 2026 Thomas von Dein
|
|
|
|
|
|
|
|
|
|
This program is free software: you can redistribute it and/or modify
|
|
|
|
|
it under the terms of the GNU General Public License as published by
|
|
|
|
|
the Free Software Foundation, either version 3 of the License, or
|
|
|
|
|
(at your option) any later version.
|
|
|
|
|
|
|
|
|
|
This program is distributed in the hope that it will be useful,
|
|
|
|
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
|
GNU General Public License for more details.
|
|
|
|
|
|
|
|
|
|
You should have received a copy of the GNU General Public License
|
|
|
|
|
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
|
*/
|
|
|
|
|
package cmd
|
|
|
|
|
|
|
|
|
|
import (
|
|
|
|
|
"context"
|
2026-05-22 13:50:17 +02:00
|
|
|
"fmt"
|
2026-04-21 10:50:09 +02:00
|
|
|
|
|
|
|
|
"codeberg.org/scip/esctl/pkg/cfg"
|
|
|
|
|
"codeberg.org/scip/esctl/pkg/es"
|
|
|
|
|
|
|
|
|
|
"github.com/urfave/cli/v3"
|
|
|
|
|
)
|
|
|
|
|
|
2026-05-29 11:05:57 +02:00
|
|
|
const SearchUsage = `<sep> might be one of:
|
2026-05-22 13:50:17 +02:00
|
|
|
=: Must match
|
|
|
|
|
!=: Must not match
|
|
|
|
|
|
|
|
|
|
You can omit a field spec and thereby search across all fields.
|
|
|
|
|
|
2026-05-29 10:19:18 +02:00
|
|
|
By default all queries contribute to matches (logical AND), use
|
|
|
|
|
-O to apply a logical OR operator.
|
|
|
|
|
|
2026-05-22 13:50:17 +02:00
|
|
|
You can also search multiple fields by separating them with comma, eg:
|
2026-05-29 10:19:18 +02:00
|
|
|
user,group=root
|
|
|
|
|
|
|
|
|
|
Use filters to further restrict results, they must match literally.
|
|
|
|
|
|
|
|
|
|
For datetime range format refer to:
|
|
|
|
|
https://www.elastic.co/docs/reference/elasticsearch/rest-apis/common-options#date-math
|
|
|
|
|
|
|
|
|
|
For timestamp formats refer to:
|
|
|
|
|
https://www.elastic.co/docs/reference/elasticsearch/mapping-reference/mapping-date-format
|
2026-05-29 11:05:57 +02:00
|
|
|
`
|
|
|
|
|
|
|
|
|
|
func Search(conf *cfg.Config) *cli.Command {
|
|
|
|
|
return &cli.Command{
|
|
|
|
|
Name: "search",
|
|
|
|
|
Aliases: []string{"/"},
|
|
|
|
|
Usage: "search within an index",
|
|
|
|
|
UsageText: "search [options] [<[field<sep>]pattern> ...]\n" + SearchUsage,
|
2026-04-21 10:50:09 +02:00
|
|
|
|
|
|
|
|
Flags: []cli.Flag{
|
|
|
|
|
&cli.StringFlag{
|
|
|
|
|
Name: "index",
|
|
|
|
|
Usage: "index to search within",
|
|
|
|
|
Sources: cli.EnvVars("ES_INDEX"),
|
|
|
|
|
Destination: &conf.Index,
|
2026-04-21 15:05:15 +02:00
|
|
|
Aliases: []string{"i"},
|
2026-04-21 10:50:09 +02:00
|
|
|
},
|
|
|
|
|
&cli.IntFlag{
|
|
|
|
|
Name: "from",
|
2026-05-29 10:19:18 +02:00
|
|
|
Usage: "show results starting at <from>",
|
2026-04-21 10:50:09 +02:00
|
|
|
Destination: &conf.From,
|
|
|
|
|
Value: 0,
|
|
|
|
|
Aliases: []string{"f"},
|
|
|
|
|
},
|
|
|
|
|
&cli.IntFlag{
|
2026-05-29 10:19:18 +02:00
|
|
|
Name: "len",
|
|
|
|
|
Usage: "number of results to show (-1: all[max:10k], caution: might be slow)",
|
2026-04-21 10:50:09 +02:00
|
|
|
Destination: &conf.To,
|
2026-05-29 10:19:18 +02:00
|
|
|
Value: 20,
|
|
|
|
|
Aliases: []string{"l"},
|
2026-04-21 10:50:09 +02:00
|
|
|
},
|
|
|
|
|
&cli.StringSliceFlag{
|
|
|
|
|
Name: "filter",
|
2026-05-22 13:50:17 +02:00
|
|
|
Usage: "additional boolean filters. format: key=value",
|
2026-04-21 10:50:09 +02:00
|
|
|
Destination: &conf.Filter,
|
|
|
|
|
Aliases: []string{"F"},
|
|
|
|
|
},
|
2026-05-22 13:50:17 +02:00
|
|
|
&cli.StringFlag{
|
|
|
|
|
Name: "jsonpath",
|
|
|
|
|
Usage: "jsonPath filter (e.g. source.message)",
|
|
|
|
|
Destination: &conf.Path,
|
|
|
|
|
Aliases: []string{"p"},
|
|
|
|
|
},
|
2026-05-29 10:19:18 +02:00
|
|
|
&cli.StringFlag{
|
|
|
|
|
Name: "timerange",
|
|
|
|
|
Usage: "field:<date> to <date> (e.g. @timestamp:2026-05-05 to 2026-05-15)",
|
|
|
|
|
Destination: &conf.Range,
|
|
|
|
|
Aliases: []string{"r"},
|
|
|
|
|
},
|
|
|
|
|
&cli.StringFlag{
|
|
|
|
|
Name: "timestamp-format",
|
|
|
|
|
Usage: "a valid ES builtin timestamp or custom format",
|
|
|
|
|
Destination: &conf.TimestampFormat,
|
|
|
|
|
Value: "strict_date_hour_minute",
|
|
|
|
|
},
|
2026-05-22 13:50:17 +02:00
|
|
|
&cli.BoolFlag{
|
|
|
|
|
Name: "help-jsonpath",
|
|
|
|
|
Usage: "show jsonPath help",
|
|
|
|
|
Destination: &conf.Subhelp,
|
|
|
|
|
Aliases: []string{"H"},
|
|
|
|
|
},
|
2026-05-29 10:19:18 +02:00
|
|
|
&cli.BoolFlag{
|
|
|
|
|
Name: "tail",
|
|
|
|
|
Usage: "follow search live, like tail -f",
|
|
|
|
|
Destination: &conf.Tail,
|
|
|
|
|
Aliases: []string{"T"},
|
|
|
|
|
},
|
|
|
|
|
&cli.BoolFlag{
|
|
|
|
|
Name: "or",
|
|
|
|
|
Usage: "logical operator (default: and)",
|
|
|
|
|
Destination: &conf.Or,
|
|
|
|
|
Aliases: []string{"O"},
|
|
|
|
|
},
|
2026-04-21 10:50:09 +02:00
|
|
|
},
|
|
|
|
|
|
|
|
|
|
Action: func(ctx context.Context, cmd *cli.Command) error {
|
2026-05-22 13:50:17 +02:00
|
|
|
if conf.Subhelp {
|
|
|
|
|
return showJsonPathHelp()
|
2026-04-21 10:50:09 +02:00
|
|
|
}
|
|
|
|
|
|
2026-05-22 13:50:17 +02:00
|
|
|
args := cmd.Args()
|
|
|
|
|
|
2026-05-29 10:19:18 +02:00
|
|
|
if conf.To == -1 {
|
|
|
|
|
conf.To = 10000
|
|
|
|
|
}
|
|
|
|
|
|
2026-05-12 18:28:57 +02:00
|
|
|
return es.Search(conf, args.Slice())
|
2026-04-21 10:50:09 +02:00
|
|
|
},
|
|
|
|
|
}
|
|
|
|
|
}
|
2026-05-22 13:50:17 +02:00
|
|
|
|
|
|
|
|
func showJsonPathHelp() error {
|
|
|
|
|
_, err := fmt.Println(`jsonPath usage:
|
|
|
|
|
|
|
|
|
|
name.last >> "Anderson"
|
|
|
|
|
age >> 37
|
|
|
|
|
children >> ["Sara","Alex","Jack"]
|
|
|
|
|
children.# >> 3
|
|
|
|
|
children.1 >> "Alex"
|
|
|
|
|
child*.2 >> "Jack"
|
|
|
|
|
c?ildren.0 >> "Sara"
|
|
|
|
|
fav\.movie >> "Deer Hunter"
|
|
|
|
|
friends.#.first >> ["Dale","Roger","Jane"]
|
|
|
|
|
friends.1.last >> "Craig"
|
|
|
|
|
|
|
|
|
|
You can also query an array for the first match by using #(...), or
|
|
|
|
|
find all matches with #(...)#. Queries support the ==, !=, <, <=, >,
|
|
|
|
|
>= comparison operators and the simple pattern matching % (like) and
|
|
|
|
|
!% (not like) operators. Eg:
|
|
|
|
|
|
|
|
|
|
friends.#(last=="Murphy").first >> "Dale"
|
|
|
|
|
friends.#(last=="Murphy")#.first >> ["Dale","Jane"]
|
|
|
|
|
friends.#(age>45)#.last >> ["Craig","Murphy"]
|
|
|
|
|
friends.#(first%"D*").last >> "Murphy"
|
|
|
|
|
friends.#(first!%"D*").last >> "Craig"
|
|
|
|
|
friends.#(nets.#(=="fb"))#.first >> ["Dale","Roger"]
|
|
|
|
|
|
|
|
|
|
Documentation: https://github.com/tidwall/gjson/blob/master/SYNTAX.md`)
|
|
|
|
|
|
|
|
|
|
return err
|
|
|
|
|
}
|