Important

This function is not available in LogScale, it is only available in Falcon NG-SIEM.

Executes a federated search query on the remote data source that generates an in-memory, ad-hoc table based on its results.

Note

  • Place all remoteTable() declarations along with any defineTable() declarations in the query preamble before other query operations (except if using the setTimeInterval() function also, then remoteTable() must be placed after this function).

  • Write remoteTable() declarations at the top level of your query. Do not nest them inside defineTable(), other functions, or subqueries.

  • It is possible to reference previously defined remote tables in subsequent defineTable() declarations.

For more information on using Ad-hoc tables, see Using Ad-hoc Tables.

Function Summary
SignatureremoteTable(connection, [end], include, name, query, [start])
Parameters for remoteTable()
ParameterTypeInterpreted TypeRequiredDefault ValueDescription
connectionstringstringrequired   The name of the federated connection used to connect to the remote data source. This needs to have already been created. Note that the connection type affects the exact parameters used in remoteTable().
endstringstringoptional[a] same as primary query End of time interval of subquery: milliseconds since UNIX epoch or a timestamp relative to the primary query's end time using Relative Time Syntax. For example: if end=7d and the main query's end time is 2024-04-10 12:00:00, then the remoteTable() subquery would use the time 2024-04-03 12:00:00 as end time.
includearray of stringsarray of stringsrequired   Fields to include as columns in the temporary table. If set to * all fields will be included.
namestringstringrequired   The name of the table in which to store federated query results. Results are limited to 200MB per table.
querystringqueryrequired   Query to execute on the remote data store. The query language used depends on the data source. For example, when querying an Amazon Athena data source, the Amazon Athena SQL would be used.
startstringstringoptional[a] same as primary query Start of time interval of subquery: milliseconds since UNIX epoch or a timestamp relative to the primary query's end time using Relative Time Syntax. For example: if start=7d and the main query's end time is 2024-03-25 14:00:00, then the remoteTable() subquery would use the time 2024-03-18 14:00:00 as start time.

[a] Optional parameters use their default value unless explicitly set.

remoteTable() Function Operation

The remoteTable() function has specific implementation and operational considerations, outlined below:

  • You must create a federated connection before remoteTable() can perform a federated search query of a remote data source.

  • Results are limited to 200MB per table, if a larger set of data is required, refine the query and run again. Federated Search can query any amount of data allowed in the target system, but only returns the first 200MB worth of results. Note that metering is based on actual table size. Due to compression overhead, the table data can exceed the 200MB limit, even if less than 200MB was retrieved.

The purpose of remoteTable() is to enable you to perform a federated search query across supported data sources.

Currently, there are two forms of remoteTable() that depend on the connection type used. The first is used with connection types that use the CQL query language for the query parameter (ExtraHop, LogScale SaaS):

logscale Syntax
remoteTable(connection, [end], include, name, query,[start])

This format has some similarities with defineTable().

The second form is used with all other connection types:

logscale Syntax
remoteTable(connection, name, query)

See Federated Search documentation for more information, including all supported connectors.

remoteTable() Syntax Examples

This section provides some examples of using remoteTable() with an Athena connector and then a LogScale SaaS connector. For more examples for other data sources see the documentation.

To return a list of available tables:

logscale Syntax
remoteTable(name="myTable", connection="myAthenaConnection", query="show tables")
| readFile("myTable")

In this case there is just one table returned, test:

test

To obtain column definitions:

logscale Syntax
remoteTable(name="myTable", connection="myAthenaConnection", query="describe test")
| readFile("myTable")

This would return results similar to the following example:

col_namecommentdatatype
transaction_id<empty string>string
customer_id<empty string>string
product_id<empty string>string

If you want to determine the structure of a table you can perform a query similar to:

logscale Syntax
remoteTable(name="myTable", connection="myAthenaConnection", query="select * from test limit 4")
| readFile("myTable")

Would return results such as:

categorycustomer_idprice
SportswearC368899
AccessoriesC493699
ElectronicsC1922999
ApparelC302899

Note that limit is used to reduce the number of returned results, simplifying the output. This is useful to manage performance and potentially reduce the cost of the query.

Example of the format for connection types using CQL as the query language:

logscale Syntax
remoteTable("MyTable", connection="LogScaleSaaSConnection", query={*}, include=[myField])
| readFile("MyTable")