/* Copyright © 2026 Thomas von Dein This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program. If not, see . */ package cmd import ( "context" "fmt" "codeberg.org/scip/esctl/pkg/cfg" "codeberg.org/scip/esctl/pkg/es" "github.com/urfave/cli/v3" ) func Search(conf *cfg.Config) *cli.Command { return &cli.Command{ Name: "search", Aliases: []string{"/"}, Usage: "search within an index", UsageText: `search [options] [<[field]pattern> ...] might be one of: =: Must match !=: Must not match ?: Should match You can omit a field spec and thereby search across all fields. You can also search multiple fields by separating them with comma, eg: user,group=root`, Flags: []cli.Flag{ &cli.StringFlag{ Name: "index", Usage: "index to search within", Sources: cli.EnvVars("ES_INDEX"), Destination: &conf.Index, Aliases: []string{"i"}, }, &cli.IntFlag{ Name: "from", Usage: "show results FROM (default 0)", Destination: &conf.From, Value: 0, Aliases: []string{"f"}, }, &cli.IntFlag{ Name: "to", Usage: "show results to (default 10)", Destination: &conf.To, Value: 10, Aliases: []string{"t"}, }, &cli.StringSliceFlag{ Name: "filter", Usage: "additional boolean filters. format: key=value", Destination: &conf.Filter, Aliases: []string{"F"}, }, &cli.StringFlag{ Name: "jsonpath", Usage: "jsonPath filter (e.g. source.message)", Destination: &conf.Path, Aliases: []string{"p"}, }, &cli.BoolFlag{ Name: "help-jsonpath", Usage: "show jsonPath help", Destination: &conf.Subhelp, Aliases: []string{"H"}, }, }, Action: func(ctx context.Context, cmd *cli.Command) error { if conf.Subhelp { return showJsonPathHelp() } args := cmd.Args() return es.Search(conf, args.Slice()) }, } } func showJsonPathHelp() error { _, err := fmt.Println(`jsonPath usage: name.last >> "Anderson" age >> 37 children >> ["Sara","Alex","Jack"] children.# >> 3 children.1 >> "Alex" child*.2 >> "Jack" c?ildren.0 >> "Sara" fav\.movie >> "Deer Hunter" friends.#.first >> ["Dale","Roger","Jane"] friends.1.last >> "Craig" You can also query an array for the first match by using #(...), or find all matches with #(...)#. Queries support the ==, !=, <, <=, >, >= comparison operators and the simple pattern matching % (like) and !% (not like) operators. Eg: friends.#(last=="Murphy").first >> "Dale" friends.#(last=="Murphy")#.first >> ["Dale","Jane"] friends.#(age>45)#.last >> ["Craig","Murphy"] friends.#(first%"D*").last >> "Murphy" friends.#(first!%"D*").last >> "Craig" friends.#(nets.#(=="fb"))#.first >> ["Dale","Roger"] Documentation: https://github.com/tidwall/gjson/blob/master/SYNTAX.md`) return err }