in

This page explains how to use the in operator in APL.

The in operator in APL filters records based on whether a value matches any element in a specified set using case-sensitive comparison. Use this operator to check if a field value equals one of several values, which is more concise and efficient than chaining multiple equality checks with or. The in operator works with any scalar type, including strings, numbers, booleans, datetime values, and dynamic arrays.

Use the in operator when you need exact case-sensitive matching against multiple values, such as filtering logs by specific status codes, identifying requests from particular regions, or isolating traces from a subset of services.

Usage

Syntax

Expression in (Value1, Value2, ...)

Parameters

NameTypeRequiredDescription
ExpressionscalarYesThe value to find in the given set.
Valuescalar or tabularYesThe values to compare against the expression. Specify individual scalar values, a dynamic array, or a subquery. When using a subquery with multiple columns, APL uses the first column. The operator supports up to 1,000,000 unique values in the set.

Returns

Returns true if the expression value is found in the specified set. Returns false otherwise.

Use case examples

Filter HTTP logs to find requests with successful status codes.

Query

['sample-http-logs']
| where status in ('200', '201', '204')
| project _time, method, uri, status

Run in Playground

Output

_timemethoduristatus
2024-10-17 10:15:00GET/api/users200
2024-10-17 10:16:30POST/api/data201
2024-10-17 10:17:45DELETE/api/item204

This query filters the HTTP logs to return only requests that resulted in successful status codes (200, 201, or 204), helping you focus on completed requests.

Identify traces from specific services in your microservices architecture.

Query

['otel-demo-traces']
| where ['service.name'] in ('frontend', 'checkout', 'cart')
| project _time, trace_id, ['service.name'], kind, duration

Run in Playground

Output

_timetrace_idservice.namekindduration
2024-10-17 11:00:00abc123frontendserver45ms
2024-10-17 11:00:05def456checkoutserver120ms
2024-10-17 11:00:10ghi789cartclient30ms

This query filters traces to show only spans from the frontend, checkout, and cart services, helping you analyze traffic flow through critical user-facing services.

Use with dynamic arrays

When you pass a dynamic array with nested arrays, APL flattens them into a single list. For instance, x in (dynamic([1, [2, 3]])) is equivalent to x in (1, 2, 3).

let methods = dynamic(['GET', 'POST']);
['sample-http-logs']
| where method in (methods)
  • !in: Use for case-sensitive matching to exclude values. Returns true if the value isn't in the set.
  • in~: Use for case-insensitive matching. Matches values regardless of case.
  • !in~: Use for case-insensitive exclusion. Excludes values regardless of case.
  • where: Use to filter rows based on conditions. The in operator is commonly used within where clauses.
  • has_any: Use for term matching against multiple values. Unlike in which checks for exact equality, has_any checks if a string contains any of the specified terms.

Other query languages