Skip to content

String Functions ​

NOTE

Verification Status: Tested and verified against the rekuiper runtime with streaming telemetry data on 2026-10-01 16:30:31 UTC.
Scorecard: 23 / 23 String Functions Fully Verified with Live Data (100% Parity):
concat, endswith, format, format_time, indexof, length, lower, lpad, ltrim, numbytes, regexp_matches, regexp_replace, regexp_substring, replace, reverse, rpad, rtrim, split, split_value, startswith, substring, trim, upper.

String functions transform, format, search, and evaluate character data.

CONCAT ​

text
concat(col1, col2, ...)

Concatenates strings or arrays. Accepts multiple arguments and returns the combined string or array.

ENDSWITH ​

text
endswith(col1, col2)

Returns true if col1 ends with col2; otherwise returns false.

FORMAT_TIME ​

text
format_time(col, format)

Formats a datetime value into a string. Converts bigint, float, or string values to datetime before formatting. Refer to format patterns.

Format_time Patterns ​

SymbolMeaningExample
GEra designatorG (AD)
YYearYYYY (2026), YY (26)
MMonth in yearM (1), MM (01), MMM (Jan), MMMM (January)
dDay in monthd (2), dd (02)
EDay name in weekEEE (Mon), EEEE (Monday)
HHour in day (0-23)HH (15)
hHour in AM/PM (1-12)h (2), hh (03)
aAM / PM markera (PM)
mMinute in hourm (4), mm (04)
sSecond in minutes (5), ss (05)
SFractional secondS (.0), SS (.00), SSS (.000)
zTime zone namez (MST)
Z4-digit time zone offsetZ (-0700)
XTime zone offsetX (-07), XX (-0700), XXX (-07:00)
\Escape prefix\Z (Z), \X (X)

Examples:

  • YYYY-MM-dd T HH:mm:ss --> 2006-01-02 T 15:04:05
  • YYYY/MM/dd HH:mm:ssSSS XXX --> 2006/01/02 15:04:05.000 -07:00
  • yyyy-MM-ddTHH:mm:ssSS\ZXX --> 2006-01-02T15:04:05.00Z-0700

INDEXOF ​

text
indexof(str, substr)

Returns the zero-based index of the first occurrence of substr in str. Returns -1 if the substring is not found:

sql
SELECT indexof(device_id, "dev") AS idx FROM demo;

LENGTH ​

text
length(col)

Returns the number of characters in the string.

LOWER ​

text
lower(col)

Converts all characters in the string to lowercase.

LPAD ​

text
lpad(col, length)

Pads the left side of col with spaces until the string reaches length characters.

LTRIM ​

text
ltrim(col)

Removes leading whitespace characters (spaces and tabs) from the string.

NUMBYTES ​

text
numbytes(col)

Returns the byte count of the UTF-8 representation of the string.

REGEXP_MATCHES ​

text
regexp_matches(col, regex)

Returns true if col contains a match for the regular expression pattern.

REGEXP_REPLACE ​

text
regexp_replace(col, regex, replacement)

Replaces all substrings in col matching regular expression regex with replacement.

REGEXP_SUBSTRING ​

text
regexp_substring(col, regex)

Returns the first substring in col that matches regular expression regex.

REPLACE ​

text
replace(source, old_substring, new_substring)

Replaces all occurrences of old_substring with new_substring without regular expression overhead:

sql
SELECT replace(status, "ACTIVE", "OK") AS status_label FROM demo;

REVERSE ​

text
reverse(col)

Reverses the order of characters in the string.

RPAD ​

text
rpad(col, length)

Pads the right side of col with spaces until the string reaches length characters.

RTRIM ​

text
rtrim(col)

Removes trailing whitespace characters (spaces and tabs) from the string.

SPLIT ​

text
split(col, delimiter)

Splits col by delimiter and returns an array of substrings:

sql
SELECT split("a,b,c", ",") AS items FROM demo;
-- Output: {"items": ["a", "b", "c"]}

SPLIT_VALUE ​

text
split_value(col, delimiter, index)

Splits col by delimiter and returns the substring at index:

sql
SELECT split_value("/test/device001/message", "/", 3) AS a FROM demo;
-- Output: {"a": "message"}

STARTSWITH ​

text
startswith(col1, col2)

Returns true if col1 starts with col2; otherwise returns false.

SUBSTRING ​

text
substring(col, start, length)

Returns a substring starting at zero-based index start with a character length of length.

TRIM ​

text
trim(col)

Removes leading and trailing whitespace characters from the string.

UPPER ​

text
upper(col)

Converts all characters in the string to uppercase.

FORMAT ​

text
format(number, decimals [, locale])

Formats numeric value number to a string rounded to decimals decimal places using optional locale conventions:

sql
SELECT format(12332.1234567, 4, "en_US");
-- Output: '12,332.1235'

Examples for 123456.78:

LocaleOutput Format
en_US123,456.78
de_DE123.456,78
de_CH123'456.78

Supported regional locales include ar_AE, ar_SA, de_DE, en_AU, en_GB, en_IN, en_US, es_ES, es_MX, fr_FR, it_IT, ja_JP, ko_KR, nl_NL, pt_BR, ru_RU, zh_CN, and zh_TW.

Released under the Apache-2.0 / MIT License.