startofday
This page explains how to use the startofday function in APL.
Use the startofday function in APL to round a datetime value down to the start of the day. The function returns midnight (00:00:00) for the date that contains the given datetime value. You can optionally shift the result by a specified number of days using the offset parameter.
You can use startofday to bin events into daily buckets for aggregation, reporting, and trend analysis across log, trace, and security datasets.
Use it when you want to:
- Group events by day for daily summaries and dashboards.
- Align timestamps to day boundaries for consistent aggregation.
- Compare metrics across different days.
Usage
Syntax
startofday(datetime [, offset])Parameters
| Name | Type | Description |
|---|---|---|
| datetime | datetime | The input datetime value. |
| offset | long | Optional: The number of days to offset from the input datetime. Default is 0. |
Returns
A datetime representing the start of the day (00:00:00) for the given date value, shifted by the offset if specified.
Use case examples
Count requests per day to identify daily traffic patterns.
Query
['sample-http-logs']
| extend day_start = startofday(_time)
| summarize request_count = count() by day_start
| sort by day_start ascOutput
| day_start | request_count |
|---|---|
| 2025-01-13T00:00:00Z | 1523 |
| 2025-01-14T00:00:00Z | 1687 |
| 2025-01-15T00:00:00Z | 1445 |
This query bins each HTTP request to the start of its day and counts the total requests per day.
Calculate the daily average span duration for each service.
Query
['otel-demo-traces']
| extend day_start = startofday(_time)
| summarize avg_duration = avg(duration) by day_start, ['service.name']
| sort by day_start ascOutput
| day_start | service.name | avg_duration |
|---|---|---|
| 2025-01-13T00:00:00Z | frontend | 00:00:01.2340000 |
| 2025-01-14T00:00:00Z | frontend | 00:00:01.1750000 |
| 2025-01-15T00:00:00Z | frontend | 00:00:01.2890000 |
This query groups trace spans by day and service, then calculates the average span duration for each combination.
Track daily error counts to identify days with unusual server error activity.
Query
['sample-http-logs']
| where toint(status) >= 500
| extend day_start = startofday(_time)
| summarize error_count = count() by day_start
| sort by day_start ascOutput
| day_start | error_count |
|---|---|
| 2025-01-13T00:00:00Z | 12 |
| 2025-01-14T00:00:00Z | 27 |
| 2025-01-15T00:00:00Z | 8 |
This query filters for server errors and counts them per day to reveal daily error patterns.
List of related functions
- endofday: Returns the end of the day for a datetime value.
- startofweek: Returns the start of the week for a datetime value.
- startofmonth: Returns the start of the month for a datetime value.
- startofyear: Returns the start of the year for a datetime value.
- bin: Rounds values down to a fixed-size bin, useful for grouping timestamps.