min_of
You typically use min_of when you want to:
- Compare numeric or time-based values across multiple fields or constants.
- Apply conditional logic in summarization or filtering steps.
- Normalize or bound values when computing metrics.
Unlike aggregation functions such as min(), which work across rows in a group, min_of operates on values within a single row or context.
Usage#
Syntax#
min_of(Expr1, Expr2, ..., ExprN)Parameters#
The function takes a comma-separated list of expressions to compare. All values must be of the same type.
Returns#
The function returns the smallest of the provided values. The type of the return value matches the type of the input arguments.
Use case example#
You have two data points for the size of HTTP responses: header size and body size. You want to find the minimum of these two values for each event.
Query
['sample-http-logs']
| extend min_size = min_of(resp_header_size_bytes, resp_body_size_bytes)
| project _time, id, resp_header_size_bytes, resp_body_size_bytes, min_sizeOutput
| _time | id | resp_header_size_bytes | resp_body_size_bytes | min_size |
|---|---|---|---|---|
| May 15, 11:31:05 | 739b0433-39aa-4891-a5e0-3bde3cb40386 | 41 B | 3,410 B | 41 |
| May 15, 11:31:05 | 3016c439-ea30-454b-858b-06f0a66f44b9 | 53 B | 5,333 B | 53 |
| May 15, 11:31:05 | b26b0a5c-bc73-4693-86ad-be9e0cc767d6 | 60 B | 2,936 B | 60 |
| May 15, 11:31:05 | 8d939423-26ae-43f7-9927-13499e7cc7d3 |
60 B | 2,896 B | 60 |
| May 15, 11:31:05 | 10c37b1a-5639-4c99-a232-c8295e3ce664 | 63 B | 4,871 B | 63 |
| May 15, 11:31:05 | 4aa1821a-6906-4ede-9417-3097efb76b89 | 78 B | 1,729 B | 78 |
| May 15, 11:31:05 | 6325de66-0033-4133-b2f3-99fa70f8c9c0 |
96 B | 4,232 B | 96 |
Other query languages#
Splunk SPL users
In Splunk, you often use the eval command with the min function to compare multiple values. APL’s min_of is similar, but used as a scalar function directly in expressions.
Splunk example
eval smallest=min(field1, field2)APL equivalent
extend smallest = min_of(field1, field2)ANSI SQL users
In SQL, you typically use LEAST() to find the smallest of multiple values. APL’s min_of is the equivalent of LEAST().
SQL example
SELECT LEAST(col1, col2, col3) AS min_val FROM table;APL equivalent
extend min_val = min_of(col1, col2, col3)