Skip to main content
The in operator in APL filters records based on whether a value matches any element in a specified set using case-sensitive comparison. Use this operator to check if a field value equals one of several values, which is more concise and efficient than chaining multiple equality checks with or. The in operator works with any scalar type, including strings, numbers, booleans, datetime values, and dynamic arrays. Use the in operator when you need exact case-sensitive matching against multiple values, such as filtering logs by specific status codes, identifying requests from particular regions, or isolating traces from a subset of services.

For users of other query languages

If you come from other query languages, this section explains how to adjust your existing queries to achieve the same results in APL.
In Splunk SPL, you use the IN function within a search or where command to check if a field value matches any value in a list. APL’s in operator works similarly but uses a different syntax with parentheses around the set of values. The APL in operator is case-sensitive by default.
In ANSI SQL, you use the IN operator within a WHERE clause to filter rows where a column value matches any value in a list. APL’s in operator behaves the same way but is case-sensitive for string comparisons.

Usage

Syntax

Parameters

Returns

Returns true if the expression value is found in the specified set. Returns false otherwise.

Use case examples

Filter HTTP logs to find requests with successful status codes.Query
Run in PlaygroundOutputThis query filters the HTTP logs to return only requests that resulted in successful status codes (200, 201, or 204), helping you focus on completed requests.

Use with dynamic arrays

When you pass a dynamic array with nested arrays, APL flattens them into a single list. For instance, x in (dynamic([1, [2, 3]])) is equivalent to x in (1, 2, 3).
  • !in: Use for case-sensitive matching to exclude values. Returns true if the value is not in the set.
  • in~: Use for case-insensitive matching. Matches values regardless of case.
  • !in~: Use for case-insensitive exclusion. Excludes values regardless of case.
  • where: Use to filter rows based on conditions. The in operator is commonly used within where clauses.
  • has_any: Use for term matching against multiple values. Unlike in which checks for exact equality, has_any checks if a string contains any of the specified terms.