Overview

isimei

You can use this function to:

  • Validate whether a string field contains a proper IMEI format.
  • Filter out malformed or suspicious entries in datasets containing device identifiers.
  • Improve data quality when analyzing logs with user agent or device metadata.

isimei is especially useful when dealing with telemetry or audit data where IMEI values are passed through APIs, headers, or form fields, and you want to ensure they conform to a valid format.

Usage#

Syntax#

isimei(value)

Parameters#

Name Type Description
value string The value to test for valid IMEI formatting.

Returns#

A bool value:

  • true if the input string is a valid IMEI number.
  • false otherwise.

A valid IMEI is a 15-digit string that passes the Luhn algorithm checksum.

Example#

Query

['sample-http-logs']
| extend has_imei = isimei('356938035643809')
| project _time, has_imei

Run in Playground

Output

_time has_imei
2025-07-10T08:21:00Z true
  • isreal: Checks whether a value is a real number.
  • iscc: Checks whether a value is a valid credit card (CC) number.
  • isstring: Checks whether a value is a string. Use this for scalar string validation.
  • isutf8: Checks whether a value is a valid UTF-8 encoded sequence.

Other query languages#

Splunk SPL users

Splunk SPL doesn’t include a built-in function for validating IMEI numbers. To replicate this logic, you typically use regular expressions and custom validation logic in eval or where clauses.

In APL, you can use isimei directly to check if a string is a valid IMEI number, simplifying your query.

Splunk example

| eval is_imei=if(match(imei_field, "^[0-9]{15}$"), "true", "false") | where is_imei="true"

APL equivalent

| where isimei(imei_field)
ANSI SQL users

ANSI SQL doesn’t include native IMEI validation functions. You typically rely on pattern matching with LIKE or regular expressions, if supported.

APL provides a dedicated isimei function to simplify this task.

SQL example

SELECT *
FROM device_logs
WHERE imei_field LIKE '[0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9]'

APL equivalent

['sample-http-logs']
| where isimei(id)

Updated

Was this page helpful?