ismap
Use ismap to:
- Filter records where a field is a map.
- Validate input types in heterogeneous data.
- Avoid runtime errors in downstream operations expecting map values.
Usage#
Syntax#
ismap(value)Parameters#
| Name | Type | Description |
|---|---|---|
value |
any | The value to check for being a map. |
Returns#
Returns true if the value is a mapping (dictionary), otherwise returns false.
Example#
Use ismap to find log entries where a dynamic field contains structured key-value pairs, such as metadata attached to HTTP requests.
Query
['sample-http-logs']
| extend is_structured = ismap(dynamic({"a":1, "b":2}))Output
| _time | is_structured |
|---|---|
| 2025-06-06T08:00:00Z | true |
List of related functions#
- isimei: Checks whether a value is a valid International Mobile Equipment Identity (IMEI) number.
- isreal: Checks whether a value is a real number.
- iscc: Checks whether a value is a valid credit card (CC) number.
- isstring: Checks whether a value is a string. Use this for scalar string validation.
- isutf8: Checks whether a value is a valid UTF-8 encoded sequence.
Other query languages#
Splunk SPL users
In Splunk SPL, you typically work with field types implicitly and rarely check if a field is a dictionary. SPL lacks a direct equivalent to APL’s ismap, but you might perform similar validations using typeof checks or custom functions in eval.
Splunk example
| eval is_map=if(typeof(field) == "object", true, false)APL equivalent
['sample-http-logs']
| extend is_map = ismap(dynamic_field)ANSI SQL users
ANSI SQL doesn’t natively support map types. If you use a platform that supports JSON or semi-structured data (such as PostgreSQL with jsonb, BigQuery with STRUCT, or Snowflake), you can simulate map checks using type inspection or schema introspection.
SQL example
SELECT
CASE
WHEN json_type(field) = 'object' THEN true
ELSE false
END AS is_map
FROM logsAPL equivalent
['sample-http-logs']
| extend is_map = ismap(dynamic_field)