Checks whether the given value matches any of the values of the array and excludes the event from the search result if it does not match any value.
Parameter | Type | Required | Default | Description |
---|---|---|---|---|
array [a] | string | required | A string in the format of a valid array followed by [] . A valid array can either be an identifier, a valid array followed by . and an identifier, or a valid array followed by an array index surrounded by square brackets. E.g., for events with fields incidents[0], incidents[1], ... this would be incidents[] . | |
value | string | required | The exact value of the array to search for. | |
[a] The argument name |
Hide omitted argument names for this function
Omitted Argument NamesThe argument name for
array
can be omitted; the following forms of this function are equivalent:logscalearray:contains("value[]",value="value")
and:
logscalearray:contains(array="value[]",value="value")
These examples show basic structure only.
Hide negatable operation for this function
Negatable Function OperationThis function is negatable, implying the inverse of the result. For example:
logscale!array:contains()
Or:
logscalenot array:contains()
For more information, see Negating the Result of Filter Functions.
A specific syntax applies for this query function, see Array Syntax for details.
array:contains()
Examples
Aggregating Array Content
Query
array:contains("incidents[]", value="Cozy Bear")
| groupBy(host)
Introduction
Given events containing an incidents
array:
Event 1
|--------------|-------------|
| host | v1 |
| incidents[0] | Evil Bear |
| incidents[1] | Cozy Bear |
|--------------|-------------|
Event 2
|--------------|-------------|
| host | v15 |
| incidents[0] | Fancy Fly |
| incidents[1] | Tiny Cat |
| incidents[2] | Cozy Bears |
|--------------|-------------|
Find all the events where the field
incidents contains the
exact value Cozy Bear
and group them by which hosts
were affected, giving output event:
Step-by-Step
Starting with the source repository events
- logscale
array:contains("incidents[]", value="Cozy Bear")
Extract elements from the array incidents from the field host that match the text
Cozy Bear
. The items will be output into the host field. - logscale
| groupBy(host)
Group the result events extracted from the array by the host.
Event Result set
Summary and Results
The result is an aggregated count of the array elements matching
Cozy Bear
.
field | value |
---|---|
host | v1 |
_count | 1 |