getschema
Usage#
Syntax#
| getschemaParameters#
The getschema operator doesn’t take any parameters.
Returns#
| Field | Type | Description |
|---|---|---|
| ColumnName | string | The name of the field in the input. |
| ColumnOrdinal | number | The index number of the field in the input. |
| ColumnType | string | The data type of the field. |
| DataType | string | The APL-internal name for the data type of the field. |
Use case example#
Query
['sample-http-logs'] | getschemaOutput
| ColumnName | DataType | ColumnOrdinal | ColumnType |
|---|---|---|---|
| _sysTime | datetime | 0 | datetime |
| _time | datetime | 1 | datetime |
| content_type | string | 2 | string |
| geo.city | string | 3 | string |
| geo.country | string | 4 | string |
| id | string | 5 | string |
List of related operators#
- project: Use
projectto select specific fields instead of retrieving the entire schema. - extend: Use
extendto add new computed fields to your input after understanding the schema. - summarize: Use
summarizefor aggregations once you verify field types usinggetschema. - where: Use
whereto filter your input based on field values after checking their schema. - order: Use
order byto sort your input after verifying schema details.
Other query languages#
Splunk SPL users
In Splunk SPL, you can use the fieldsummary command to get schema-related information about your data. However, getschema in APL is more direct and focused specifically on returning field names and types without additional summary statistics.
Splunk example
| fieldsummaryAPL equivalent
['sample-http-logs']
| getschemaANSI SQL users
In ANSI SQL, retrieving schema information is typically done using INFORMATION_SCHEMA queries. APL’s getschema operator provides a more straightforward way to get schema details without requiring system views.
SQL example
SELECT COLUMN_NAME, DATA_TYPE FROM INFORMATION_SCHEMA.COLUMNS WHERE TABLE_NAME = 'sample_http_logs';APL equivalent
['sample-http-logs']
| getschema