CONST
Learn how to write a \[CONST\] section in a Parsing Rules file and the syntax to use.
A CONST section is used to define strings and numbers that can be reused multiple times within Cortex Query Language (XQL) statements in other INGEST sections by using $constName. This can be helpful to avoid writing the same value in multiple sections, similar to constants in modern programming languages.
Example:
[CONST]
DEFAULT_DEVICE_NAME = "firewall3060"; // string
FILE_REGEX = "c:\\users\\[a-zA-Z0-9.]*"; // complex string
my_num = 3; /* int */An example of using a CONST inside XQL statements in other INGEST sections using $constName:
...
| filter device_name = $DEFAULT_DEVICE_NAME
| alter new_field = JSON_EXTRACT(field, $FILE_REGEX)
| filter age < $MAX_TIMEOUT
| join type=$DEFAULT_JOIN_TYPE conflict_strategy=$DEFAULT_JOIN_CONFLICT_STRATEGY (dataset=my_lookup) as inn url=inn.url
...Example:
These will not compile:
CONST sections are meant to replace values. Other types, such as column names, are not supported:
A few more points to keep in mind when writing CONST sections:
CONSTnames are not case-sensitive. They can be written in any user-desired casing, such as UPPER_SNAKE, lower_snake, camelCase, and CamelCase. For example,MY_CONST=My_Const=my_const.CONSTnames must be unique inside a section, and across all sections of the file. You cannot have the sameCONSTname defined again in the same section, or in any otherCONSTsections in the file.Since section order is unimportant, you do not have to declare a
CONSTbefore using it. You can have theCONSTsection written below other sections that use thoseCONSTsections.A
CONSTis an add-on to the Parsing Rule syntax and is optional to configure.CONSTsyntax is derived from XQL, but a few modifications as explained in the Parsing Rules syntax.
Last updated
Was this helpful?
