Hi Everyone
I am trying to create an investigation in ES using SPL.
Since ES is most work as lookup/kvstore, so I try to run the following SPL
| makeresults
| eval class_name="investigation",
collaborators="[{\"name\": \"AAAAAA\", \"write\": true}, {\"name\": \"BBBBBB\", \"write\": true}]",
create_time=1668731443,
creator="CCCCCC",
description="DDDDDDD",
mod_time=1668731608,
status="[{\"name\": \"In Progress\", \"time\": 1668739809, \"id\": \"investigation:2\"}]",
title="EEEEEEE",
version=1,
comments="[]",
tags="[]"
| table class_name, collaborators, create_time, creator, description, mod_time, status, title, version, comments, tags | outputlookup append=true investigation