/* Copyright © 2026 Thomas von Dein This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program. If not, see . */ package es import ( "context" "encoding/json" "fmt" "log/slog" "codeberg.org/scip/esctl/pkg/cfg" "codeberg.org/scip/esctl/pkg/printer" ) type searchQlColumn struct { Name string `json:"name"` Type string `json:"type"` } type searchQlResult struct { Partial bool `json:"is_partial"` Docs int `json:"documents_found"` Columns []searchQlColumn `json:"columns"` Values [][]any `json:"values"` } func SearchQL(conf *cfg.Config, querystring string) error { query := conf.DefaultCluster.ES().Esql.Query(). Query(querystring). DropNullColumns(true) res, err := query.Do(context.Background()) if err != nil { return fmt.Errorf("failed to run esql query: %w", esErrorString(err)) } if conf.Debug { fmt.Println(string(res)) } qlResult := searchQlResult{} if err = json.Unmarshal(res, &qlResult); err != nil { return fmt.Errorf("failed to unmarshal esql result: %w", err) } slog.Debug("searchql result", "qlres", qlResult) if qlResult.Docs == 0 { return nil } table := printer.NewTable(conf, len(qlResult.Columns), len(qlResult.Values)) headers := make([]string, len(qlResult.Columns)) for idx, col := range qlResult.Columns { headers[idx] = col.Name } table.Addheaders(headers...) table.Entries = qlResult.Values return table.Print() }