Overview

array_iff

Usage#

Syntax#

array_iff(condition_array, array1, array2)

Parameters#

  • condition_array: An array of boolean values, where each element determines whether to choose the corresponding element from array1 or array2.
  • array1: The array to select elements from when the corresponding condition_array element is true.
  • array2: The array to select elements from when the corresponding condition_array element is false.

Returns#

An array where each element is selected from array1 if the corresponding condition_array element is true, and from array2 otherwise.

Use case examples#

The array_iff function can help filter log data conditionally, such as choosing specific durations based on HTTP status codes.

Query

['sample-http-logs']
| order by _time desc
| limit 1000
| summarize is_ok = make_list(status == '200'), request_duration = make_list(req_duration_ms)
| project ok_request_duration = array_iff(is_ok, request_duration, 0)

Run in Playground

Output

ok_request_duration
[0.3150485097707766, 0, 0.21691408087847264, 0, 0.2757618582190533]

This example filters the req_duration_ms field to include only durations for the most recent 1,000 requests with status 200, replacing others with 0.

With OpenTelemetry trace data, you can use array_iff to filter spans based on the service type, such as selecting durations for server spans and setting others to zero.

Query

['otel-demo-traces']
| order by _time desc
| limit 1000
| summarize is_server = make_list(kind == 'server'), duration_list = make_list(duration)
| project server_durations = array_iff(is_server, duration_list, 0)

Run in Playground

Output

server_durations
["45.632µs", "54.622µs", 0, "34.051µs"]

In this example, array_iff selects durations only for server spans, setting non-server spans to 0.

In security logs, array_iff can be used to focus on specific cities in which HTTP requests originated, such as showing response durations for certain cities and excluding others.

Query

['sample-http-logs']
| limit 1000
| summarize is_london = make_list(['geo.city'] == "London"), request_duration = make_list(req_duration_ms)
| project london_duration = array_iff(is_london, request_duration, 0)

Run in Playground

Output

london_duration
[100, 0, 250]

This example filters the req_duration_ms array to show durations for requests from London, with non-matching cities having 0 as duration.

Other query languages#

Splunk SPL users

In Splunk SPL, array manipulation based on conditions typically requires using conditional functions or eval expressions. APL’s array_iff function lets you directly select elements from one array or another based on a condition, offering more streamlined array manipulation.

Splunk example

eval selected_array=if(condition, array1, array2)

APL equivalent

array_iff(condition_array, array1, array2)
ANSI SQL users

In ANSI SQL, conditionally selecting elements from arrays often requires complex CASE statements or functions. With APL’s array_iff function, you can directly compare arrays and conditionally populate them, simplifying array-based operations.

SQL example

CASE WHEN condition THEN array1 ELSE array2 END

APL equivalent

array_iff(condition_array, array1, array2)

Updated

Was this page helpful?