isstring
You can use isstring to:
- Filter rows based on whether a field is a string.
- Validate and clean data before applying string functions.
- Avoid runtime errors in queries that expect specific data types.
Usage#
Syntax#
isstring(value)Parameters#
| Name | Type | Description |
|---|---|---|
value |
any | The value to test for string type. |
Returns#
A bool value that’s true if the input value is of type string, false otherwise.
Use case example#
Use isstring to filter rows where the HTTP status code is a valid string.
Query
['sample-http-logs']
| extend is_string = isstring(status)
| where is_stringOutput
| _time | status | is_string |
|---|---|---|
| 2025-06-05T12:10:00Z | "404" | true |
This query filters out logs where the status field is stored as a string, which can help filter out ingestion issues or schema inconsistencies.
List of related functions#
- isimei: Checks whether a value is a valid International Mobile Equipment Identity (IMEI) number.
- isreal: Checks whether a value is a real number.
- iscc: Checks whether a value is a valid credit card (CC) number.
- isutf8: Checks whether a value is a valid UTF-8 encoded sequence.
Other query languages#
Splunk SPL users
In Splunk SPL, type checking is typically implicit and not exposed through a dedicated function like isstring. Instead, you often rely on function compatibility and casting behavior. In APL, isstring provides an explicit and reliable way to check if a value is a string before further processing.
Splunk example
| eval type=if(isstr(field), "string", "not string")APL equivalent
['sample-http-logs']
| extend type=iff(isstring(status), 'string', 'not string')ANSI SQL users
ANSI SQL doesn’t include a built-in IS STRING function. Instead, type checks usually rely on schema constraints, manual casting, or vendor-specific solutions. In contrast, APL offers isstring as a first-class function that returns a boolean indicating whether a value is of type string.
SQL example
SELECT
CASE
WHEN typeof(status) = 'VARCHAR' THEN 'string'
ELSE 'not string'
END AS type
FROM logsAPL equivalent
['sample-http-logs']
| extend type=iff(isstring(status), 'string', 'not string')