Overview

genai_get_content_by_index

You can use this function to extract specific messages in a conversation flow, analyze conversation structure, retrieve intermediate messages, or process conversations sequentially.

Usage#

Syntax#

genai_get_content_by_index(messages, index)

Parameters#

Name Type Required Description
messages dynamic Yes An array of message objects from a GenAI conversation. Each message typically contains role and content fields.
index long Yes The zero-based position of the message to retrieve. Use 0 for the first message, 1 for the second, etc.

Returns#

Returns a string containing the content of the message at the specified index, or an empty string if the index is out of bounds.

Example#

Get the content of the first user message in a GenAI conversation.

Query

['otel-demo-genai']
| extend first_message = genai_get_content_by_index(['attributes.gen_ai.input.messages'], 1)
| where isnotempty(first_message)
| project _time, first_message
| limit 3

Run in Playground

Output

_time first_message
2024-01-15T10:30:00Z Hello, I need help with my account.
2024-01-15T10:31:00Z Can you tell me about your services?

This query helps you understand how users typically start conversations, which can inform greeting messages and initial prompts.

  • genai_get_content_by_role: Gets content filtered by role. Use this when you need messages from a specific role rather than a specific position.
  • genai_get_role: Gets the role at a specific index. Combine with this function to understand both role and content at positions.
  • array_length: Returns array length. Use this to check message count before accessing by index.
  • genai_extract_user_prompt: Extracts the last user prompt. Use this when you need the most recent user message instead of a specific index.
  • genai_extract_assistant_response: Extracts the last assistant response. Use this when you need the most recent AI response.

Other query languages#

Splunk SPL users

In Splunk SPL, you would use mvindex to access array elements by position.

Splunk example

| eval message_content=mvindex(messages, 2)

APL equivalent

['ai-logs']
| extend message_content = genai_get_content_by_index(messages, 2)
ANSI SQL users

In ANSI SQL, you would unnest the array and use OFFSET to access specific positions.

SQL example

SELECT
  conversation_id,
  content as message_content
FROM conversations
CROSS JOIN UNNEST(messages) WITH OFFSET AS pos
WHERE pos = 2

APL equivalent

['ai-logs']
| extend message_content = genai_get_content_by_index(messages, 2)

Updated

Was this page helpful?