Overview

set_union

You can use set_union when you need to merge two arrays and eliminate duplicates. It’s especially useful in scenarios where you need to perform set-based logic, such as comparing user activity across multiple sources, correlating IPs from different datasets, or combining traces or log attributes from different events.

Usage#

Syntax#

set_union(Array1, Array2)

Parameters#

Name Type Description
Array1 dynamic The first array to merge.
Array2 dynamic The second array to merge.

Returns#

A dynamic array that contains the distinct elements of both input arrays.

Example#

Use set_union to return the union of two arrays.

Query

['sample-http-logs']
| extend together = set_union(dynamic([1, 2, 3]), dynamic([2, 3, 4, 5]))

Run in Playground

Output

_time together
May 22, 11:42:52 [1, 2, 3, 4, 5 ]
  • set_difference: Returns elements in the first array that aren’t in the second. Use it to find exclusions.
  • set_has_element: Tests whether a set contains a specific value. Prefer it when you only need a Boolean result.
  • set_union: Returns the union of two or more sets. Use it when you need any element that appears in at least one set instead of every set.

Other query languages#

Splunk SPL users

APL’s set_union works similarly to using mvappend followed by mvdedup in SPL. While SPL stores multivalue fields and uses field-based manipulation, APL focuses on dynamic arrays. You need to explicitly apply set logic in APL using functions like set_union.

Splunk example

| eval result=mvappend(array1, array2)
| eval result=mvdedup(result)

APL equivalent

extend result = set_union(array1, array2)
ANSI SQL users

Standard SQL doesn’t support arrays as first-class types or set functions like set_union. However, conceptually, set_union behaves like applying UNION between two subqueries that return one column each, followed by a DISTINCT.

SQL example

SELECT value FROM (
  SELECT value FROM table1
  UNION
  SELECT value FROM table2
)

APL equivalent

extend result = set_union(array1, array2)

Updated

Was this page helpful?