trim
Introduction#
Use the trim function when you want to normalize or clean string values by stripping unwanted characters such as quotes, spaces, slashes, or punctuation. It’s useful in log analysis, standardizing OpenTelemetry attributes, or cleaning identifiers in security logs.
Usage#
Syntax#
trim(cutset, source)Parameters#
| Name | Type | Required | Description |
|---|---|---|---|
| cutset | string | ✓ | The set of characters to remove from both the beginning and end of source. |
| source | string | ✓ | The source string to process. |
Returns#
A string with all leading and trailing characters removed that match any character in the cutset.
Use case examples#
You can use trim to normalize URLs by removing leading and trailing slashes before grouping.
Query
['sample-http-logs']
| extend clean_uri = trim("/", uri)
| summarize count() by clean_uriOutput
| clean_uri | count |
|---|---|
| api/login | 120 |
| product/details | 85 |
| cart/add | 62 |
This query removes leading and trailing slashes from the uri field so that identical paths group consistently.
In traces, you can use trim to standardize service names by removing surrounding underscores or dashes.
Query
['otel-demo-traces']
| extend clean_service = trim("-_", ['service.name'])
| summarize avg(duration) by clean_serviceOutput
| clean_service | avg_duration |
|---|---|
| frontend | 120ms |
| cart | 210ms |
| checkout | 310ms |
This query ensures service names are consistent before calculating averages.
When analyzing user IDs, you can use trim to remove unwanted wrapping characters, such as hashes or quotes.
Query
['sample-http-logs']
| extend clean_id = trim("#", id)
| summarize count() by clean_idOutput
| clean_id | count |
|---|---|
| user123 | 42 |
| user456 | 38 |
| user789 | 55 |
This query strips hashes around user IDs so they can be counted reliably.
Other query languages#
Splunk SPL users
In Splunk SPL, the trim function removes characters from both ends of a string, using a list of characters. APL’s trim works the same way: it uses a cutset of characters, not a regular expression.
Splunk example
... | eval cleaned=trim(field, "-")APL equivalent
print s='--https://axiom.co--'
| extend cleaned=trim("--", s)ANSI SQL users
In ANSI SQL, TRIM removes whitespace or specified characters from both ends of a string. APL’s trim works similarly, but instead of supporting keywords like BOTH, LEADING, or TRAILING, it uses separate functions: trim for both ends, ltrim for the start, and rtrim for the end. Like SQL, it operates on characters, not regular expressions.
SQL example
SELECT TRIM(BOTH '-' FROM '--hello--');APL equivalent
print s='--hello--'
| extend cleaned=trim("--", s)