Skip to main content
Use the indexof_regex function to find the position of the first match of a regular expression in a string. The function is helpful when you want to locate a pattern within a larger text field and take action based on its position. For example, you can use indexof_regex to extract fields from semi-structured logs, validate string formats, or trigger alerts when specific patterns appear in log data. The function returns the zero-based index of the first match. If no match is found, it returns -1. Use indexof_regex when you need more flexibility than simple substring search (indexof), especially when working with dynamic or non-fixed patterns.
All regex functions of APL use the RE2 regex syntax.

For users of other query languages

If you come from other query languages, this section explains how to adjust your existing queries to achieve the same results in APL.
Use match() in Splunk SPL to perform regular expression matching. However, match() returns a Boolean, not the match position. APL’s indexof_regex is similar to combining match() with additional logic to extract position, which isn’t natively supported in SPL.
ANSI SQL doesn’t have a built-in function to return the index of a regex match. You typically use REGEXP_LIKE for Boolean evaluation. indexof_regex provides a more direct and powerful way to find the exact match position in APL.

Usage

Syntax

Parameters

Returns

The function returns the position (starting at zero) where the pattern first matches within the string. If the pattern isn’t found, the result is -1. The function returns null in the following cases:
  • The start value is negative.
  • The occurrence value is less than 1.
  • The length is set to a value below -1.

Use case examples

Use indexof_regex to detect whether the URI in a log entry contains an encoded user ID by checking for patterns like user-[0-9]+.Query
Run in PlaygroundOutputThe query finds log entries where the URI contains a user ID pattern and shows the position of the match in the URI string.