tobool
You typically use tobool when working with data that represents boolean values as strings (like "true"/"false" or "1"/"0"), numbers, or other types that need to be converted to proper boolean values.
Usage#
Syntax#
tobool(value)Parameters#
| Name | Type | Description |
|---|---|---|
| value | dynamic | The value to convert to boolean. |
Returns#
If conversion is successful, the result is a boolean. If conversion isn’t successful, the result is false.
Conversion behavior#
The tobool function converts values based on their type:
- Boolean: Returns the value unchanged.
- Integer/Float/Duration: Returns
trueif the value isn't equal to 0, otherwisefalse. - Datetime: Returns
trueif the value is anything other than epoch (zero time), otherwisefalse. - String: Returns
trueif the value equals"1","t","T","TRUE","true", or"True". Returnsfalseif the value equals"0","f","F","FALSE","false", or"False". Returnsnullfor any other string value.
Example#
Convert string representations of Boolean values to actual Boolean types for filtering and analysis.
Query
['sample-http-logs']
| extend is_active = tobool(is_active)
| extend is_enabled = tobool(enabled)
| where is_active == true or is_enabled == true
| project _time, uri, status, is_active, enabled, is_active, is_enabledOutput
| _time | uri | status | is_active | enabled | is_active | is_enabled |
|---|---|---|---|---|---|---|
| Jun 24, 09:28:10 | /api/users | 200 | "true" | "1" | true | true |
This example converts string representations of boolean values (like "true" and "1") to actual boolean types, enabling proper boolean logic and filtering.
List of related functions#
- isbool: Checks if a value is a boolean. Use
isboolto validate types, andtoboolto convert values to boolean. - case: Evaluates conditions and returns values. Use
casefor complex conditional logic, andtoboolfor simple conversions. - iff: Returns one of two values based on a predicate. Use
ifffor conditional assignment, andtoboolfor type conversion.
Other query languages#
Splunk SPL users
In Splunk, you use if expressions or tonumber with comparisons to convert values to boolean-like results. In APL, tobool provides a direct conversion function that handles various input types.
Splunk example
... | eval is_active = if(field == "true" OR field == 1, 1, 0)APL equivalent
... | extend is_active = tobool(field)ANSI SQL users
In standard SQL, you use CASE statements or CAST to convert values to boolean. In APL, tobool provides a simpler way to convert various types to boolean values.
SQL example
SELECT CASE WHEN status = 'active' THEN TRUE ELSE FALSE END AS is_active FROM logs;APL equivalent
['sample-http-logs']
| extend is_active = tobool(is_active)