string_size
This page explains how to use the string_size function in APL.
The string_size function returns the number of bytes in a string. You use it when you want to measure the length of text fields such as user IDs, URLs, or status codes. This function is useful for detecting anomalies, filtering out unusually long values, or analyzing patterns in textual data.
For example, you can use string_size to detect requests with excessively long URIs, identify outlier user IDs, or monitor payload lengths in traces.
Usage
Syntax
Parameters
| Parameter | Type | Description |
|---|---|---|
source | string | The input string expression. |
Returns
An integer representing the number of bytes in the string. If the string is empty, the function returns 0.
Use case examples
You can use string_size to detect unusually long URIs that might indicate an attempted exploit or malformed request.
Query
Output
| _time | method | uri | uri_length | status |
|---|---|---|---|---|
| 2025-09-11T10:01:45Z | GET | /search/products?q=... | 142 | 200 |
| 2025-09-11T10:02:13Z | POST | /checkout/submit/order/details... | 187 | 400 |
This query finds all HTTP requests with URIs longer than 10 characters and lists their details.
You can measure the length of trace IDs or span IDs to ensure data consistency and identify malformed identifiers.
Query
Output
| service.name | avg_length |
|---|---|
| frontend | 32 |
| checkoutservice | 32 |
| loadgenerator | 31.8 |
This query calculates the average trace ID length per service to verify identifier consistency across the system.
You can check for anomalous user IDs by looking at the length of the id field. Very short or very long IDs may signal invalid or suspicious activity.
Query
Output
| _time | id | id_length | status | geo.country |
|---|---|---|---|---|
| 2025-09-11T09:55:01Z | a12 | 3 | 401 | US |
| 2025-09-11T09:58:42Z | user_long_id_example_test | 24 | 200 | DE |
This query detects requests with suspiciously short or long user IDs, which might indicate invalid credentials or malicious activity.