Overview

range

range is useful when you want to produce test values, synthetic sequences, time intervals, or loop-like constructs without relying on input data. It helps you populate arrays that can be expanded or joined with real data for further analysis.

Usage#

Syntax#

range(start, stop [, step])

Parameters#

Name Type Required Description
start scalar (number, datetime, timespan) ✓ First value in the array.
stop scalar (same type as start) ✓ Upper bound of the array. The last value is less than or equal to stop.
step scalar (same type as start) Difference between values. Defaults to 1 (numeric) or 1h (time).

Returns#

A dynamic array that includes values starting at start, incremented by step, up to and including stop (if it aligns exactly with a step). The array truncates if it reaches the system limit of 1,048,576 elements.

Use case examples#

Generate an array of durations to help classify HTTP request latencies.

Query

print r = range(100, 500, 100)
| project r

Run in Playground

Output

[
  100,
  200,
  300,
  400,
  500
]

This creates an array of thresholds that you can use to bucket or filter request durations in ['sample-http-logs'].

Build a set of time intervals to align span activity over a fixed period.

Query

print intervals = range(datetime(2025-07-29T12:00:00Z), datetime(2025-07-29T13:00:00Z), 15m)
| project intervals

Run in Playground

Output

[
  "2025-07-29T12:00:00Z",
  "2025-07-29T12:15:00Z",
  "2025-07-29T12:30:00Z",
  "2025-07-29T12:45:00Z",
  "2025-07-29T13:00:00Z"
]

This array helps divide the hour into 15-minute blocks for analyzing activity in ['otel-demo-traces'].

Create a list of expected hourly intervals to detect missing logs.

Query

print expected = range(datetime(2025-07-29T00:00:00Z), datetime(2025-07-29T05:00:00Z), 1h)
| project expected

Run in Playground

Output

[
  "2025-07-29T00:00:00Z",
  "2025-07-29T01:00:00Z",
  "2025-07-29T02:00:00Z",
  "2025-07-29T03:00:00Z",
  "2025-07-29T04:00:00Z",
  "2025-07-29T05:00:00Z"
]

This produces an array of expected log collection times for the ['sample-http-logs'] dataset. You can join this with actual data to detect missing records.

Other query languages#

Splunk SPL users

In SPL, generating sequences often involves makeresults combined with streamstats or manual iteration logic. APL’s range function simplifies this by producing arrays of equally spaced values directly.

Splunk example

| makeresults count=10
| streamstats count as x

APL equivalent

print r = range(1, 10, 1)
ANSI SQL users

In ANSI SQL, generating a series of numbers usually involves recursive CTEs. APL’s range is more concise and efficient for creating sequences without writing complex recursion logic.

SQL example

WITH RECURSIVE seq AS (
  SELECT 1 AS x
  UNION ALL
  SELECT x + 1 FROM seq WHERE x < 10
)
SELECT * FROM seq;

APL equivalent

print r = range(1, 10, 1)

Updated

Was this page helpful?