Field Interactions
LogScale UI offers contextual menus for various interactions with fields. What interactions are supported depends on the Field Data Types of the selected field.
To access these menus:
Locate the ⋮ icon next to a field in any of these areas:
Click the ⋮ icon to open the contextual menu. In the example screenshot below, the field interaction menu is opened from the Results panel:
![]() |
Figure 73. Field Interactions
Available interactions are:
Query editor. It works in any field interaction within the Fields panel and Inspection panel. It also works in the Event list when the data type is JSON or Log line.
— copies the value or the field's name, which you can paste in theYou can copy the field in different formats:
Additional interactions are available on both value fields and name fields. These are:
array:contains()
query function to query data. It only shows for JSON array fields. Two options are available:Event List, it is possible to filter for any user who has WRITE permissions, independent on where the WRITE value is in the array. The following query is applied when this interaction is selected:
filters events by requiring a string value to be present in the array. For example, given a list of users with different access permissions in thelogscalearray:contains("user.permissions[]", value=WRITE)
Event List, it is possible to filter any user who does not have WRITE permissions. The following query applies when using this interaction:
allows for inverted filters, meaning it filters events by requiring a string value that is not present in the array. For example, given a list of users with different access permissions in thelogscalenot array:contains("user.permissions[]", value=WRITE)
Note
Because
array:contains()
checks for a single value at the time, you must run multiple Array interactions, if you wish to filter on multiple values in the array.
actor.ip . This option allows for filtering IP values by appending specific query functions. IP interaction options include:
— available on fields that contain IP addresses, such asipLocation()
function. The new query uses the name of the selected IP field as thefield
argument.worldMap()
query function. The new query uses the name of the selected IP field as theip
argument.ioc:lookup()
query function. The new query uses the name of the selected IP field as thefield
argument. Click and IP field, say ip_address, to generate a new query in the Query editor, like this:logscaleioc:lookup(field=[actor.ip], type="ip_address", confidenceThreshold="unverified", strict=true)
Note
Numbers that exceed the range of safe integers in Javascript are replaced in JSON by reading the associated LogScale value directly. This is to avoid that incorrect numbers are displayed. These replaced numbers are highlighted in JSON data to indicate that they might be wrong. For more information, see Troubleshooting: UI Warning: The actual value is different from what is displayed.
When LogScale detects a JSON string in a field, it displays the
→ option in the menu.When LogScale detects a URL in a field, it displays the
→ option in the menu. This option splits the URL into its component parts.
Time Chart
with individual series for each value in the selected field.timeChart()
percentile query.
When you hover over one of the available options under
timeChart()
to the query, for the
#repo field.
![]() |
Figure 74. Query Update Tooltip
Tip
Use SHIFT+click to add the suggested option to the query string without running a new search.