Overview

todynamic

You often find todynamic helpful when working with logs, telemetry, or security events that encode rich metadata or nested attributes in stringified JSON. By converting these strings into dynamic values, you can query, filter, and transform the nested fields using APL’s built-in support for dynamic types.

Usage#

Syntax#

todynamic(value)

Parameters#

Name Type Description
value string A string representing a JSON-encoded object or array.

Returns#

A dynamic value. If the input isn’t a valid JSON string, the function returns null.

Example#

You want to find events that match certain criteria such as URI and status code. The criteria are stored in a stringified dictionary.

Query

['sample-http-logs']
| extend criteria = '{"uri": "/api/v1/customer/services", "status": "200"}'
| extend metadata = todynamic(criteria)
| where uri == metadata.uri and status == metadata.status
| project _time, id

Run in Playground

Output

_time id
Jun 24, 09:28:10 2f2e5c40-1094-4237-a124-ec50fab7e726
Jun 24, 09:28:10 0f9724cb-fa9a-4a2f-bdf6-5c32b2f22efd
Jun 24, 09:28:10 a516c4e9-2ed9-4fb9-a191-94e2844e9b2a
  • pack_array: Use this to combine scalar values into an array. Use pack_array when you don’t need named keys and want positional data instead.
  • bag_keys: Returns the list of keys in a dynamic dictionary. Use this to inspect or filter contents created by pack_dictionary.
  • bag_pack: Expands a dictionary into multiple columns. Use it to revert the packing performed by pack_dictionary.

Other query languages#

Splunk SPL users

Splunk automatically interprets structured JSON data and allows you to use dot notation directly on fields, without explicit conversion. In APL, you need to explicitly cast a JSON string into a dynamic value using todynamic.

Splunk example

... | eval json_field = json_extract(raw_field, "$.key")

APL equivalent

... | extend json_field = todynamic(raw_field).key
ANSI SQL users

In standard SQL, you typically use JSON_VALUE, JSON_QUERY, or CAST(... AS JSON) to access structured content in string format. In APL, use todynamic to convert a string to a dynamic value that supports dot notation and further manipulation.

SQL example

SELECT JSON_VALUE(raw_column, '$.key') AS value FROM logs;

APL equivalent

['sample-http-logs']
| extend value = todynamic(raw_column).key

Updated

Was this page helpful?