genai_get_content_by_index
You can use this function to extract specific messages in a conversation flow, analyze conversation structure, retrieve intermediate messages, or process conversations sequentially.
Usage#
Syntax#
genai_get_content_by_index(messages, index)Parameters#
| Name | Type | Required | Description |
|---|---|---|---|
| messages | dynamic | Yes | An array of message objects from a GenAI conversation. Each message typically contains role and content fields. |
| index | long | Yes | The zero-based position of the message to retrieve. Use 0 for the first message, 1 for the second, etc. |
Returns#
Returns a string containing the content of the message at the specified index, or an empty string if the index is out of bounds.
Example#
Get the content of the first user message in a GenAI conversation.
Query
['otel-demo-genai']
| extend first_message = genai_get_content_by_index(['attributes.gen_ai.input.messages'], 1)
| where isnotempty(first_message)
| project _time, first_message
| limit 3Output
| _time | first_message |
|---|---|
| 2024-01-15T10:30:00Z | Hello, I need help with my account. |
| 2024-01-15T10:31:00Z | Can you tell me about your services? |
This query helps you understand how users typically start conversations, which can inform greeting messages and initial prompts.
List of related functions#
- genai_get_content_by_role: Gets content filtered by role. Use this when you need messages from a specific role rather than a specific position.
- genai_get_role: Gets the role at a specific index. Combine with this function to understand both role and content at positions.
- array_length: Returns array length. Use this to check message count before accessing by index.
- genai_extract_user_prompt: Extracts the last user prompt. Use this when you need the most recent user message instead of a specific index.
- genai_extract_assistant_response: Extracts the last assistant response. Use this when you need the most recent AI response.
Other query languages#
Splunk SPL users
In Splunk SPL, you would use mvindex to access array elements by position.
Splunk example
| eval message_content=mvindex(messages, 2)APL equivalent
['ai-logs']
| extend message_content = genai_get_content_by_index(messages, 2)ANSI SQL users
In ANSI SQL, you would unnest the array and use OFFSET to access specific positions.
SQL example
SELECT
conversation_id,
content as message_content
FROM conversations
CROSS JOIN UNNEST(messages) WITH OFFSET AS pos
WHERE pos = 2APL equivalent
['ai-logs']
| extend message_content = genai_get_content_by_index(messages, 2)