todynamic
You often find todynamic helpful when working with logs, telemetry, or security events that encode rich metadata or nested attributes in stringified JSON. By converting these strings into dynamic values, you can query, filter, and transform the nested fields using APL’s built-in support for dynamic types.
Usage#
Syntax#
todynamic(value)Parameters#
| Name | Type | Description |
|---|---|---|
| value | string | A string representing a JSON-encoded object or array. |
Returns#
A dynamic value. If the input isn’t a valid JSON string, the function returns null.
Example#
You want to find events that match certain criteria such as URI and status code. The criteria are stored in a stringified dictionary.
Query
['sample-http-logs']
| extend criteria = '{"uri": "/api/v1/customer/services", "status": "200"}'
| extend metadata = todynamic(criteria)
| where uri == metadata.uri and status == metadata.status
| project _time, idOutput
| _time | id |
|---|---|
| Jun 24, 09:28:10 | 2f2e5c40-1094-4237-a124-ec50fab7e726 |
| Jun 24, 09:28:10 | 0f9724cb-fa9a-4a2f-bdf6-5c32b2f22efd |
| Jun 24, 09:28:10 | a516c4e9-2ed9-4fb9-a191-94e2844e9b2a |
List of related functions#
- pack_array: Use this to combine scalar values into an array. Use
pack_arraywhen you don’t need named keys and want positional data instead. - bag_keys: Returns the list of keys in a dynamic dictionary. Use this to inspect or filter contents created by
pack_dictionary. - bag_pack: Expands a dictionary into multiple columns. Use it to revert the packing performed by
pack_dictionary.
Other query languages#
Splunk SPL users
Splunk automatically interprets structured JSON data and allows you to use dot notation directly on fields, without explicit conversion. In APL, you need to explicitly cast a JSON string into a dynamic value using todynamic.
Splunk example
... | eval json_field = json_extract(raw_field, "$.key")APL equivalent
... | extend json_field = todynamic(raw_field).keyANSI SQL users
In standard SQL, you typically use JSON_VALUE, JSON_QUERY, or CAST(... AS JSON) to access structured content in string format. In APL, use todynamic to convert a string to a dynamic value that supports dot notation and further manipulation.
SQL example
SELECT JSON_VALUE(raw_column, '$.key') AS value FROM logs;APL equivalent
['sample-http-logs']
| extend value = todynamic(raw_column).key