Overview

isstring

You can use isstring to:

  • Filter rows based on whether a field is a string.
  • Validate and clean data before applying string functions.
  • Avoid runtime errors in queries that expect specific data types.

Usage#

Syntax#

isstring(value)

Parameters#

Name Type Description
value any The value to test for string type.

Returns#

A bool value that’s true if the input value is of type string, false otherwise.

Use case example#

Use isstring to filter rows where the HTTP status code is a valid string.

Query

['sample-http-logs']
| extend is_string = isstring(status)
| where is_string

Run in Playground

Output

_time status is_string
2025-06-05T12:10:00Z "404" true

This query filters out logs where the status field is stored as a string, which can help filter out ingestion issues or schema inconsistencies.

  • isimei: Checks whether a value is a valid International Mobile Equipment Identity (IMEI) number.
  • isreal: Checks whether a value is a real number.
  • iscc: Checks whether a value is a valid credit card (CC) number.
  • isutf8: Checks whether a value is a valid UTF-8 encoded sequence.

Other query languages#

Splunk SPL users

In Splunk SPL, type checking is typically implicit and not exposed through a dedicated function like isstring. Instead, you often rely on function compatibility and casting behavior. In APL, isstring provides an explicit and reliable way to check if a value is a string before further processing.

Splunk example

| eval type=if(isstr(field), "string", "not string")

APL equivalent

['sample-http-logs']
| extend type=iff(isstring(status), 'string', 'not string')
ANSI SQL users

ANSI SQL doesn’t include a built-in IS STRING function. Instead, type checks usually rely on schema constraints, manual casting, or vendor-specific solutions. In contrast, APL offers isstring as a first-class function that returns a boolean indicating whether a value is of type string.

SQL example

SELECT
  CASE
    WHEN typeof(status) = 'VARCHAR' THEN 'string'
    ELSE 'not string'
  END AS type
FROM logs

APL equivalent

['sample-http-logs']
| extend type=iff(isstring(status), 'string', 'not string')

Updated

Was this page helpful?