unicode_codepoints_to_string

This page explains how to use the unicode_codepoints_to_string function in APL.

Use the unicode_codepoints_to_string function to convert an array of Unicode code points into a UTF-8 encoded string. This function is helpful when your data represents characters as numeric values—such as integer arrays from encodings, logs, or telemetry fields—and you want to decode them into readable text.

You can use unicode_codepoints_to_string to reconstruct log messages, parse encoded payloads, or normalize fragmented character sequences for visualization, comparison, or filtering.

Usage

Syntax

unicode_codepoints_to_string(array)

Parameters

NameTypeDescription
arraydynamicAn array of integers representing Unicode code points.

Returns

A string constructed from the given Unicode code points using UTF-8 encoding.

Use case examples

Sometimes HTTP logs store user-agent strings or query parameters as numeric arrays for compact storage. You can use unicode_codepoints_to_string to decode those sequences.

Query

['sample-http-logs']
| extend codepoints = dynamic([72, 84, 84, 80])
| extend decoded_method = unicode_codepoints_to_string(codepoints)
| project _time, decoded_method

Run in Playground

Output

_timedecoded_method
2025-07-29T14:12:00ZHTTP

This query decodes the static Unicode array [72, 84, 84, 80] into the string 'HTTP'.

In tracing systems, service metadata might be emitted as numeric codes for efficiency. You can use unicode_codepoints_to_string to interpret those codes during post-processing.

Query

['otel-demo-traces']
| where ['service.name'] == 'checkout'
| extend trace_label_codepoints = dynamic([67, 72, 69, 67, 75])
| extend decoded_label = unicode_codepoints_to_string(trace_label_codepoints)
| project _time, trace_id, ['service.name'], decoded_label

Run in Playground

Output

_timetrace_id['service.name']decoded_label
2025-07-29T14:20:00Zd4e9aefb8cc31b4dcheckoutCHECK

The query decodes a fixed array into the label 'CHECK' to tag traces visually in dashboards.

Sometimes security tools emit obfuscated payloads as numeric arrays. You can decode and inspect them using unicode_codepoints_to_string.

Query

['sample-http-logs']
| extend obfuscated_uri = dynamic([47, 108, 111, 103, 105, 110])
| extend decoded_uri = unicode_codepoints_to_string(obfuscated_uri)
| project _time, uri, decoded_uri

Run in Playground

Output

_timeuridecoded_uri
2025-07-29T14:30:00Z/blocked/login

This example shows how to reconstruct a denied URI (/login) from its obfuscated form using code points.

  • array_concat: Combines multiple arrays. Useful when merging code point arrays from different strings.
  • array_length: Returns the number of elements in an array. Use it to check how many code points a string contains.
  • parse_path: Parses a path into components. Use it with unicode_codepoints_from_string when decoding or inspecting URL paths.
  • unicode_codepoints_from_string: Converts a UTF-8 string into an array of Unicode code points.

Other query languages