Overview

todouble, toreal

You typically use todouble when working with numeric strings, integers, or other types that need to be converted to floating-point numbers for precise calculations or when decimal precision is required.

Usage#

Syntax#

todouble(value)
toreal(value)

Parameters#

Name Type Description
value dynamic The value to convert to real.

Returns#

If conversion is successful, the result is a value of type real. If conversion isn't successful, the result is null.

Conversion behavior#

The todouble function converts values based on their type:

  • Integer: Converted to float. For example, 1 becomes 1.0, -1 becomes -1.0.
  • String: Parsed as a 64-bit float using Go floating-point literal syntax, which supports scientific notation. For example, "1e3" becomes 1000.0.
  • Boolean: true becomes 1.0, false becomes 0.0
  • Datetime: Converted to nanoseconds since epoch as a float
  • Duration: Converted to float nanoseconds

Use case examples#

Convert string representations of numeric values to real numbers for mathematical calculations and aggregations.

Query

['sample-http-logs']
| extend duration_seconds = todouble(['req_duration_ms']) / 1000.0
| extend is_slow = duration_seconds > 0.001
| where is_slow == true
| project _time, ['uri'], ['req_duration_ms'], duration_seconds, is_slow

Run in Playground

Output

_time uri req_duration_ms duration_seconds is_slow
Jun 24, 09:28:10 /api/users 1500 1.5 true

This example converts milliseconds to seconds using todouble to ensure decimal precision in the calculation, enabling accurate time-based analysis.

Convert trace duration values to real numbers for precise duration calculations and percentile analysis.

Query

['otel-demo-traces']
| extend duration_ms = todouble(['duration']) / 1000000.0
| extend is_slow_span = duration_ms > 100.0
| where is_slow_span == true
| project _time, ['trace_id'], ['service.name'], ['duration'], duration_ms, is_slow_span

Run in Playground

Output

_time trace_id service.name duration duration_ms is_slow_span
Jun 24, 09:28:10 abc123 frontend 150000000 150.0 true

This example converts nanosecond durations to milliseconds using todouble to maintain decimal precision, enabling accurate performance analysis of trace spans.

Convert numeric security metrics to real numbers for threshold-based security analysis and alerting.

Query

['sample-http-logs']
| extend risk_score = todouble(['req_duration_ms']) / 100.0
| extend is_high_risk = risk_score > 0.01
| where is_high_risk == true
| project _time, ['uri'], ['status'], ['req_duration_ms'], risk_score, is_high_risk

Run in Playground

Output

_time uri status req_duration_ms risk_score is_high_risk
Jun 24, 09:28:10 /admin 403 5500 55.0 true

This example converts request duration to a risk score using todouble to enable precise threshold-based security analysis with decimal precision.

  • toreal: Synonym for todouble. Both functions convert values to real numbers.
  • toint: Converts input to integer. Use toint when you need whole numbers, and todouble when you need decimal precision.

Other query languages#

Splunk SPL users

In Splunk, you use tonumber to convert values to numbers, which handles both integers and decimals. In APL, todouble specifically converts to floating-point numbers, while toint or tolong handle integers.

Splunk example

... | eval price = tonumber(price_string)

APL equivalent

... | extend price = todouble(price_string)
ANSI SQL users

In standard SQL, you use CAST(... AS DOUBLE) or CAST(... AS REAL) to convert values to floating-point numbers. In APL, todouble and toreal are synonyms that provide a simpler way to convert to real numbers.

SQL example

SELECT CAST('1567.89' AS DOUBLE) AS price FROM logs;

APL equivalent

['sample-http-logs']
| extend price = todouble('1567.89')

Updated

Was this page helpful?