Important
This function is not available in LogScale, it is only available in Falcon NG-SIEM.
Executes a federated search query on the remote data source that generates an in-memory, ad-hoc table based on its results.
Note
Place all
remoteTable()declarations along with anydefineTable()declarations in the query preamble before other query operations (except if using thesetTimeInterval()function also, thenremoteTable()must be placed after this function).Write
remoteTable()declarations at the top level of your query. Do not nest them insidedefineTable(), other functions, or subqueries.It is possible to reference previously defined remote tables in subsequent
defineTable()declarations.
For more information on using Ad-hoc tables, see Using Ad-hoc Tables.
Function Summary| Signature | remoteTable(connection, [end], include, name, query, [start]) |
remoteTable()| Parameter | Type | Interpreted Type | Required | Default Value | Description |
|---|---|---|---|---|---|
connection | string | string | required | Â | The name of the federated connection used to connect to the remote data source. This needs to have already been created. Note that the connection type affects the exact parameters used in remoteTable(). |
end | string | string | optional[a] | same as primary query | End of time interval of subquery: milliseconds since UNIX epoch or a timestamp relative to the primary query's end time using Relative Time Syntax. For example: if end=7d and the main query's end time is 2024-04-10 12:00:00, then the remoteTable() subquery would use the time 2024-04-03 12:00:00 as end time. |
include | array of strings | array of strings | required | Â | Fields to include as columns in the temporary table. If set to * all fields will be included. |
name | string | string | required | Â | The name of the table in which to store federated query results. Results are limited to 200MB per table. |
query | string | query | required | Â | Query to execute on the remote data store. The query language used depends on the data source. For example, when querying an Amazon Athena data source, the Amazon Athena SQL would be used. |
start | string | string | optional[a] | same as primary query | Start of time interval of subquery: milliseconds since UNIX epoch or a timestamp relative to the primary query's end time using Relative Time Syntax. For example: if start=7d and the main query's end time is 2024-03-25 14:00:00, then the remoteTable() subquery would use the time 2024-03-18 14:00:00 as start time. |
[a] Optional parameters use their default value unless explicitly set. | |||||
remoteTable() Function Operation
The remoteTable() function has specific
implementation and operational considerations, outlined below:
You must create a federated connection before
remoteTable()can perform a federated search query of a remote data source.Results are limited to 200MB per table, if a larger set of data is required, refine the query and run again. Federated Search can query any amount of data allowed in the target system, but only returns the first 200MB worth of results. Note that metering is based on actual table size. Due to compression overhead, the table data can exceed the 200MB limit, even if less than 200MB was retrieved.
The purpose of remoteTable() is to enable
you to perform a federated search query across supported data
sources.
Currently, there are two forms of
remoteTable() that depend on the
connection type used. The first is used with connection types
that use the CQL query language for the query parameter
(ExtraHop, LogScale SaaS):
remoteTable(connection, [end], include, name, query,[start])
This format has some similarities with
defineTable().
The second form is used with all other connection types:
remoteTable(connection, name, query)See Federated Search documentation for more information, including all supported connectors.
remoteTable() Syntax Examples
This section provides some examples of using
remoteTable() with an Athena connector
and then a LogScale SaaS connector. For more examples for
other data sources see
the
documentation.
To return a list of available tables:
remoteTable(name="myTable", connection="myAthenaConnection", query="show tables")
| readFile("myTable")
In this case there is just one table returned,
test:
| test |
To obtain column definitions:
remoteTable(name="myTable", connection="myAthenaConnection", query="describe test")
| readFile("myTable")This would return results similar to the following example:
| col_name | comment | datatype |
|---|---|---|
| transaction_id | <empty string> | string |
| customer_id | <empty string> | string |
| product_id | <empty string> | string |
If you want to determine the structure of a table you can perform a query similar to:
remoteTable(name="myTable", connection="myAthenaConnection", query="select * from test limit 4")
| readFile("myTable")Would return results such as:
| category | customer_id | price |
|---|---|---|
| Sportswear | C368 | 899 |
| Accessories | C493 | 699 |
| Electronics | C192 | 2999 |
| Apparel | C302 | 899 |
Note that limit is used to reduce the number of
returned results, simplifying the output. This is useful to
manage performance and potentially reduce the cost of the
query.
Example of the format for connection types using CQL as the query language:
remoteTable("MyTable", connection="LogScaleSaaSConnection", query={*}, include=[myField])
| readFile("MyTable")