/* Copyright © 2026 Thomas von Dein This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program. If not, see . */ package cmd import ( "context" "codeberg.org/scip/esctl/pkg/cfg" "codeberg.org/scip/esctl/pkg/es" "github.com/urfave/cli/v3" ) const SearchUsage = `field might be one of: =: Must match !=: Must not match You can omit a field spec and thereby search across all fields. By default all queries contribute to matches (logical AND), use -O to apply a logical OR operator. You can also search multiple fields by separating them with comma, eg: user,group=root Use filters to further restrict results, they must match literally. For datetime range format refer to: https://www.elastic.co/docs/reference/elasticsearch/rest-apis/common-options#date-math For timestamp formats refer to: https://www.elastic.co/docs/reference/elasticsearch/mapping-reference/mapping-date-format` func Search(conf *cfg.Config) *cli.Command { return &cli.Command{ Name: "search", Aliases: []string{"/"}, Usage: "search within an index", UsageText: "search [options] [<[field]pattern> ...]\n", CustomHelpTemplate: addReference(SearchUsage), Flags: []cli.Flag{ &cli.StringFlag{ Name: "index", Usage: "index to search within", Sources: cli.EnvVars("ES_INDEX"), Destination: &conf.Index, Aliases: []string{"i"}, }, &cli.IntFlag{ Name: "from", Usage: "show results starting at ", Destination: &conf.From, Value: 0, Aliases: []string{"f"}, }, &cli.IntFlag{ Name: "len", Usage: "number of results to show (-1: all[max:10k], caution: might be slow)", Destination: &conf.To, Value: 20, Aliases: []string{"l"}, }, &cli.StringSliceFlag{ Name: "filter", Usage: "additional boolean filters. format: key=value", Destination: &conf.Filter, Aliases: []string{"F"}, }, &cli.StringFlag{ Name: "jsonpath", Usage: "jsonPath filter (e.g. source.message)", Destination: &conf.Path, Aliases: []string{"p"}, }, &cli.StringFlag{ Name: "timerange", Usage: "field: to (e.g. @timestamp:2026-05-05 to 2026-05-15)", Destination: &conf.Range, Aliases: []string{"r"}, }, &cli.StringFlag{ Name: "timestamp-format", Usage: "a valid ES builtin timestamp or custom format", Destination: &conf.TimestampFormat, Value: "strict_date_hour_minute", }, &cli.StringFlag{ Name: "sort-by", Usage: "sort by a field", Destination: &conf.SortBy, Value: "@timestamp", Aliases: []string{"k"}, }, &cli.BoolFlag{ Name: "ascending", Usage: "sort in ascending order (default: descending)", Destination: &conf.Ascending, Aliases: []string{"a"}, }, &cli.BoolFlag{ Name: "tail", Usage: "follow search live, like tail -f", Destination: &conf.Tail, Aliases: []string{"T"}, }, &cli.BoolFlag{ Name: "or", Usage: "logical operator (default: and)", Destination: &conf.Or, Aliases: []string{"O"}, }, &cli.BoolFlag{ Name: "validate", Usage: "validate search query", Destination: &conf.Validate, Aliases: []string{"v"}, }, &cli.BoolFlag{ Name: "explain", Usage: "explain search query", Destination: &conf.Explain, Aliases: []string{"e"}, }, }, Action: func(ctx context.Context, cmd *cli.Command) error { args := cmd.Args() if conf.To == -1 { conf.To = 10000 } return es.Search(conf, args.Slice()) }, } }