Miscellaneous operators :: Kloudfuse Docs
Miscellaneous operators
Table of Contents
- backshift
- base64Decode
- base64Encode
- compareCIDRPrefix
- concat
- decToHex
- dedup
- format
- formatDate
- getCIDRPrefix
- hash
- hexToAscii
- hexToDec
- in
- ipv4ToNumber
- isBlank
- isEmpty
- isNumeric
- isPrivateIP
- isPublicIP
- isValidIP
- len
- luhn
- maskFromCIDR
- matches
- now
- parseDate
- queryEndTime
- queryStartTime
- queryTimeRange
- replace
- substring
- timeslice
- toBytes
- toDuration
- toFloat
- toInt
- toLowerCase
- toUpperCase
- transpose
- trim
- urlDecode
- urlEncode
Using these functions in the Advanced Search interface allows for relatively complex data transformations. The Logs Query Builder does not natively support these functions.
Operators
backshift
Shifts a column in a table down by the specified number.
Syntax
| backshift <field>
| backshift <field> as <alias>
| backshift <field>, <number>
| backshift <field>, <number> as <alias>
base64Decode
Converts a base64 string into to an ASCII/UTF-8 string.
Syntax
| base64Decode(<base64String>) as <alias>
Example:
| base64Decode("SGVsbG8gV29ybGQ=") as K
base64Encode
Converts an ASCII/UTF-8 string to a base64 string.
Syntax
| base64Encode(<string>) as <alias>
Example:
| base64Encode("Hello World") as K
compareCIDRPrefix
Checks if the network prefixes of two IPv4 addresses match.
Syntax
| compareCIDRPrefix(<ipv4String>, <ipv4String>) as <alias>
Example:
| compareCIDRPrefix("10.10.1.35", "10.10.1.35", 24) as K
concat
Concatenates multiple strings and numbers into a new string.
Syntax
| concat(<field1>, <field2>, ...) as <alias>
Example:
| concat("Hello", " ", "World", " ", 1) as K
decToHex
Converts long value to hexadecimal value.
Syntax
| decToHex(<longField>) as <alias>
Example:
| decToHex("70") as K
dedup
Removes duplicate results in a table by a set of columns.
Syntax
| dedup by <field1>, <field2>, ...
| dedup by <number> <field1>, <field2>, ...
format
Returns a formatted string given a format specifier and arguments.
Syntax
| format(<formatSpecifierString>, <field1>, ...) as <alias>
Example:
| format("%s : %s", "The count is", 1) as K
formatDate
Returns a date string given a date, format, and timezone (default UTC).
Syntax
| formatDate(<dateMilliseconds>) as <alias>
| formatDate(<dateMilliseconds>, <formatString>) as <alias>
| formatDate(<dateMilliseconds>, <formatString>, <timezoneString>) as <alias>
Example:
| formatDate(1730925217838) as K
getCIDRPrefix
Retrieves the network prefix from an IPv4 address.
Syntax
| getCIDRPrefix(<ipv4String>) as <alias>
Example:
| getCIDRPrefix("10.10.1.35") as K
hash
Hashes data into a string value using the specified hash algorithm.
Syntax
| hash(<field>) as <alias>
| hash(<field>, <hashAlgorithm>) as <alias>
Example:
| hash("hello world") as K
hexToAscii
Converts hexadecimal string to ASCII value.
Syntax
| hexToAscii(<hexString>) as <alias>
Example:
| hexToAscii("48656c6c6f20476f7068657221") as K
hexToDec
Converts hexadecimal string to a long value.
Syntax
| hexToDec(<hexString>) as <alias>
Example:
| hexToDec("0000000000001337") as K
in
Checks if a field is in a set of string values or number values.
Syntax
| where <field> in (<value_1>[, <value_2>, <value_3>, ...])
ipv4ToNumber
Converts an Internet Protocol version 4 (IPv4) IP address from the octet dot-decimal format to a decimal format.
Syntax
| ipv4ToNumber(<ipv4String>) as <alias>
Example:
| ipv4ToNumber("10.163.3.0") as K
isBlank
Checks if a string value is null, empty, or contains only empty characters.
Syntax
| isBlank(<string>) as <alias>
Example:
| isBlank(" ") as K
isEmpty
Checks if a string value is an empty string that contains no characters or whitespace.
Syntax
| isEmpty(<string>) as <alias>
Example:
| isEmpty(" a ") as K
isNumeric
Checks if a string value can be parsed as a number.
Syntax
| isNumeric(<string>) as <alias>
Example:
| isNumeric("1.234") as K
isPrivateIP
Checks if an IPv4 address is private.
Syntax
| isPrivateIP(<ipv4String>) as <alias>
Example:
| isPrivateIP("192.168.0.1") as K
isPublicIP
Checks if an IPv4 address is public.
Syntax
| isPublicIP(<ipv4String>) as <alias>
Example:
| isPrivateIP("192.168.0.1") as K
isValidIP
Checks if an IPv4 or IPv6 address is valid.
Syntax
| isValidIP(<ipString>) as <alias>
Example:
| isValidIP("192.168.0.1") as K
len
Returns the length of a string.
Syntax
| len(<string>) as <alias>
Example:
| len("1234") as K
luhn
Validates credit card numbers in a string value using Luhn’s algorithm.
Syntax
| luhn(<string>) as <alias>
Example:
| luhn("6666-7777-6666-8888") as K
maskFromCIDR
Returns the subnet mask given a prefix length for IPv4 addresses.
Syntax
| maskFromCIDR(<prefixLength>) as <alias>
Example:
| maskFromCIDR(32) as K
matches
Matches strings using the RE2-compliant regex format.
Syntax
| where <string expression> matches "<regex>"
Example:
| source="pinot-server" | parse "[*]" as class | where class matches "Server.*"
now
Returns the current epoch time in milliseconds.
Syntax
| now() as <alias>
Example:
| now() as K
parseDate
Parses a date string with the given format pattern and optional timezone (default UTC), and returns the corresponding epoch milliseconds.
Syntax
| parseDate(<dateString>, <formatString>) as <alias>
Example:
| parseDate("2024-11-06 20:33:37", "yyyy-MM-dd HH:mm:ss") as K
queryEndTime
Returns the end time of the search in milliseconds.
Syntax
| queryEndTime() as <alias>
Example:
| queryEndTime() as K
queryStartTime
Returns the start time of the search in milliseconds.
Syntax
| queryStartTime() as <alias>
Example:
| queryStartTime() as K
queryTimeRange
Returns the time range for the query being executed, in milliseconds.
Syntax
| queryTimeRange() as <alias>
Example:
| queryTimeRange() as K
replace
Replaces all occurrences of a specified string with another string.
Syntax
| replace(<sourceString>, <searchString>, <replaceString>) as <alias>
Example:
| replace("hello world", "world", "gopher") as K
substring
Extracts a part of a given string and start/end offsets.
Syntax
| substring(<sourceString>, <startOffsert>) as <alias>
Example:
| substring("hello world", 0, 5) as K
timeslice
Buckets each event’s timestamp into fixed-width time windows for use in time-series aggregation.
Syntax
| timeslice <duration>
Example:
* | timeslice 5m | count by (_timeslice)
toBytes
Parses a string representation of bytes (KB, MB, GB, and so on) into the number of bytes it represents.
Syntax
| toBytes(<storageSize>) as <alias>
Example:
| toBytes("1.5KB") as K
toDuration
Parses a string representation of time (ns, µs, ms, s, m, h) to milliseconds.
Syntax
| toDuration(<timeString>) as <alias>
Example:
| toDuration("2ms") as K
toFloat
Parses a string representation of a number or a number to a float.
Syntax
| toFloat(<number>) as <alias>
Example:
| toFloat("1.25") as K
toInt
Parses a string representation of a number, or a number to an int.
Syntax
| toInt(<number>) as <alias>
Example:
| toInt("1.5") as K
toLowerCase
Converts all letters of a string to lowercase.
Syntax
| toLowerCase(<string>) as <alias>
Example:
| toLowerCase("HELLO WORLD") as K
toUpperCase
Converts all letters of a string to uppercase.
Syntax
| toUpperCase(<string>) as <alias>
Example:
| toUpperCase("hello world") as K
transpose
Converts aggregate query results from a long format into a wide, tabular format by pivoting row values into column headers.
Syntax
| transpose row <row_field1>[, <row_field2>, ...] column <column_field1>[, <column_field2>, ...]
trim
Removes starting and trailing empty spaces in a string.
Syntax
| trim(<string>) as <alias>
Example:
| trim(" hello world ") as K
urlDecode
Returns an unescaped URL string.
Syntax
| urlDecode(<urlString>) as <alias>
Example:
| urlDecode("http%3A%2F%2Fexample-server123.org%2Fapi%2Fv1%2Fdata.php%3Fauth%3DAbCdEfGhIjKlMnOpQrStUvWxYz123456%26") as K
urlEncode
Encodes a URL into the ASCII character set.
Syntax
| urlEncode(<urlString>) as <alias>
Example:
| urlEncode("http://example-server123.org/api/v1/data.php?auth=AbCdEfGhIjKlMnOpQrStUvWxYz123456&") as K