OverviewHistoryStatsSecurity
npx skills add ...
Documentation
SKILL.md
npx skills add axiomhq/skills --skill spl-to-apl
Translates Splunk SPL queries to Axiom APL. Provides command mappings, function equivalents, and syntax transformations. Use when migrating from Splunk, converting SPL queries, or learning APL equivalents of SPL patterns.
npx skills add axiomhq/skills --skill spl-to-apl
Type safety: Fields like status are often stored as strings. Always cast before numeric comparison: toint(status) >= 500, not status >= 500.
where _time between (ago(1h) .. now())index=... | command → APL ['dataset'] | operatorcidrmatch(cidr, ip) → APL ipv4_is_in_range(ip, cidr)| SPL | APL | Notes |
|---|---|---|
search index=... | ['dataset'] | Dataset replaces index |
search field=value | where field == "value" | Explicit where |
where | where | Same |
stats | summarize | Different aggregation syntax |
eval | extend | Create/modify fields |
table / fields | project | Select columns |
fields - | project-away | Remove columns |
rename x as y | project-rename y = x | Rename |
sort / sort - | order by ... asc/desc | Sort |
head N | take N | Limit rows |
top N field | summarize count() by field | top N by count_ | Two-step |
dedup field | summarize arg_max(_time, *) by field | Keep latest |
rex | parse or extract() | Regex extraction |
join | join | Preview feature |
append | union | Combine datasets |
mvexpand | mv-expand | Expand arrays |
timechart span=X | summarize ... by bin(_time, X) | Manual binning |
rare N field | summarize count() by field | order by count_ asc | take N | Bottom N |
spath | parse_json() or json['path'] | JSON access |
transaction | No direct equivalent | Use summarize + make_list |
Complete mappings: reference/command-mapping.md
| SPL | APL |
|---|---|
count | count() |
count(field) | countif(isnotnull(field)) |
dc(field) | dcount(field) |
avg/sum/min/max | Same |
median(field) | percentile(field, 50) |
perc95(field) | percentile(field, 95) |
first/last | arg_min/arg_max(_time, field) |
list(field) | make_list(field) |
values(field) | make_set(field) |
Complete function list: reference/function-mapping.md
| SPL | APL | Notes |
|---|---|---|
if(c, t, f) | iff(c, t, f) | Double 'f' |
case(c1,v1,...) | case(c1,v1,...,default) | Requires default |
len(str) | strlen(str) | |
lower/upper | tolower/toupper | |
substr | substring | 0-indexed in APL |
replace | replace_string | |
tonumber | toint/tolong/toreal | Explicit types |
match(s,r) | s matches regex "r" | Operator |
split(s, d) | split(s, d) | Same |
mvjoin(mv, d) | strcat_array(arr, d) | Join array |
mvcount(mv) | array_length(arr) | Array length |
Note: SPL's 1==1 catch-all becomes implicit default in APL.
SPL time pickers don't translate. Always add explicit time range:
| SPL | APL | Speed |
|---|---|---|
field="value" | field == "value" | Fastest |
field="*value*" | field contains "value" | Moderate |
field="value*" | field startswith "value" | Fast |
match(field, regex) | field matches regex "..." | Slowest |
Prefer has over contains (word-boundary matching is faster). Use _cs variants for case-sensitive (faster).
reference/command-mapping.md — complete command listreference/function-mapping.md — complete function listreference/examples.md — full query translation examples