Record functions allow you to create records or extract data from them.
Creates a record from the keys and values of the parameter.
record(expression, …)
| Parameter | Type | Description | Required |
|---|---|---|---|
expression | array, boolean, double, duration, ip, long, record, string, timeframe, timestamp | An expression to add to the record. | Required |
The data type of the returned value is record.
data record(executable = "java", technologies = array("Java", "Spring", "Jetty")),record(executable = "python", technologies = array("Python", "Flask")),record(executable = "java", technologies = array("Java", "Jetty", "Hibernate"))
Query result:
| executable | technologies |
|---|---|
|
|
|
|
|
|
Returns the value of a single field from a record by name.
The recordField function is the record counterpart to jsonField, which extracts a value by name from a JSON string.
recordField(record, name)
| Parameter | Type | Description | Required |
|---|---|---|---|
record | record | The record to extract the field value from. | Required |
name | string | The name of the field to extract. | Required |
The data type of the returned value depends on the type of the named field in the record.
The following example uses recordField to extract the host field from a nested metadata record.
data record(event = "failed to find product",metadata = record(host = "web-1", region = "us-east-1"))| fieldsAdd recordField(metadata, "host")
Query result:
| event | metadata | recordField(metadata, "host") |
|---|---|---|
| host: |
|
Returns all fields of a record as an array of key-value pairs.
Each element in the returned array is a record with two fields: key (the field name as a string) and value (the field value). The function is non-recursive: if a field value is itself a record, it's returned as-is, not expanded.
The resulting array can be used with field access notation—out[][key] yields an array of all keys, and out[][value] yields an array of all values. To reconstruct a record from key-value pairs, use recordFromFields.
recordFields(record)
| Parameter | Type | Description | Required |
|---|---|---|---|
record | record | The record to convert to an array of key-value pairs. | Required |
The data type of the returned value is array. Each element is a record with fields key (string) and value.
The following example converts the nested metadata record into an array of key-value pair records.
data record(event = "failed to find product",metadata = record(host = "web-1", region = "us-east-1"))| fieldsAdd recordFields(metadata)
Query result:
| event | metadata | recordFields(metadata) |
|---|---|---|
| host: | [key: |
The following example shows how to use array field access notation to get all keys and all values from the result of recordFields.
data record(metadata = record(host = "web-1", region = "us-east-1", env = "prod"))| fieldsAdd pairs = recordFields(metadata)| fieldsAdd keys = pairs[]["key"], values = pairs[]["value"]| fieldsRemove pairs
Query result:
| metadata | keys | values |
|---|---|---|
host: |
|
|
Creates a record from an array of key-value pairs.
The recordFromFields function is the inverse of recordFields. It takes an array of records, each with a key field (string) and a value field, and assembles them into a single record.
recordFromFields(fields)
| Parameter | Type | Description | Required |
|---|---|---|---|
fields | array | An array of records, each containing a | Required |
The data type of the returned value is record.
The following example converts a record to key-value pairs using recordFields, then reconstructs it using recordFromFields.
data record(metadata = record(host = "web-1", region = "us-east-1"))| fieldsAdd pairs = recordFields(metadata)| fieldsAdd reconstructed = recordFromFields(pairs)| fieldsRemove pairs
Query result:
| metadata | reconstructed |
|---|---|
host: | host: |
Returns the field names of a record as an array of strings.
recordKeys(record)
| Parameter | Type | Description | Required |
|---|---|---|---|
record | record | The record whose field names to return. | Required |
The data type of the returned value is array. Each element is a string.
The following example returns the field names of the nested metadata record.
data record(metadata = record(host = "web-1", region = "us-east-1", env = "prod"))| fieldsAdd recordKeys(metadata)
Query result:
| metadata | recordKeys(metadata) |
|---|---|
host: |
|
Returns the field values of a record as an array.
recordValues(record)
| Parameter | Type | Description | Required |
|---|---|---|---|
record | record | The record whose field values to return. | Required |
The data type of the returned value is array. The type of each element depends on the corresponding field value in the record.
The following example returns the field values of the nested metadata record.
data record(metadata = record(host = "web-1", region = "us-east-1", env = "prod"))| fieldsAdd recordValues(metadata)
Query result:
| metadata | recordValues(metadata) |
|---|---|
host: |
|