String Functions
NOTE
Verification Status: Tested and verified against the rekuiper runtime with streaming telemetry data on 2026-10-01 16:30:31 UTC.
Scorecard: 23 / 23 String Functions Fully Verified with Live Data (100% Parity):concat, endswith, format, format_time, indexof, length, lower, lpad, ltrim, numbytes, regexp_matches, regexp_replace, regexp_substring, replace, reverse, rpad, rtrim, split, split_value, startswith, substring, trim, upper.
String functions transform, format, search, and evaluate character data.
CONCAT
concat(col1, col2, ...)Concatenates strings or arrays. Accepts multiple arguments and returns the combined string or array.
ENDSWITH
endswith(col1, col2)Returns true if col1 ends with col2; otherwise returns false.
FORMAT_TIME
format_time(col, format)Formats a datetime value into a string. Converts bigint, float, or string values to datetime before formatting. Refer to format patterns.
Format_time Patterns
| Symbol | Meaning | Example |
|---|---|---|
G | Era designator | G (AD) |
Y | Year | YYYY (2026), YY (26) |
M | Month in year | M (1), MM (01), MMM (Jan), MMMM (January) |
d | Day in month | d (2), dd (02) |
E | Day name in week | EEE (Mon), EEEE (Monday) |
H | Hour in day (0-23) | HH (15) |
h | Hour in AM/PM (1-12) | h (2), hh (03) |
a | AM / PM marker | a (PM) |
m | Minute in hour | m (4), mm (04) |
s | Second in minute | s (5), ss (05) |
S | Fractional second | S (.0), SS (.00), SSS (.000) |
z | Time zone name | z (MST) |
Z | 4-digit time zone offset | Z (-0700) |
X | Time zone offset | X (-07), XX (-0700), XXX (-07:00) |
\ | Escape prefix | \Z (Z), \X (X) |
Examples:
YYYY-MM-dd T HH:mm:ss-->2006-01-02 T 15:04:05YYYY/MM/dd HH:mm:ssSSS XXX-->2006/01/02 15:04:05.000 -07:00yyyy-MM-ddTHH:mm:ssSS\ZXX-->2006-01-02T15:04:05.00Z-0700
INDEXOF
indexof(str, substr)Returns the zero-based index of the first occurrence of substr in str. Returns -1 if the substring is not found:
SELECT indexof(device_id, "dev") AS idx FROM demo;LENGTH
length(col)Returns the number of characters in the string.
LOWER
lower(col)Converts all characters in the string to lowercase.
LPAD
lpad(col, length)Pads the left side of col with spaces until the string reaches length characters.
LTRIM
ltrim(col)Removes leading whitespace characters (spaces and tabs) from the string.
NUMBYTES
numbytes(col)Returns the byte count of the UTF-8 representation of the string.
REGEXP_MATCHES
regexp_matches(col, regex)Returns true if col contains a match for the regular expression pattern.
REGEXP_REPLACE
regexp_replace(col, regex, replacement)Replaces all substrings in col matching regular expression regex with replacement.
REGEXP_SUBSTRING
regexp_substring(col, regex)Returns the first substring in col that matches regular expression regex.
REPLACE
replace(source, old_substring, new_substring)Replaces all occurrences of old_substring with new_substring without regular expression overhead:
SELECT replace(status, "ACTIVE", "OK") AS status_label FROM demo;REVERSE
reverse(col)Reverses the order of characters in the string.
RPAD
rpad(col, length)Pads the right side of col with spaces until the string reaches length characters.
RTRIM
rtrim(col)Removes trailing whitespace characters (spaces and tabs) from the string.
SPLIT
split(col, delimiter)Splits col by delimiter and returns an array of substrings:
SELECT split("a,b,c", ",") AS items FROM demo;
-- Output: {"items": ["a", "b", "c"]}SPLIT_VALUE
split_value(col, delimiter, index)Splits col by delimiter and returns the substring at index:
SELECT split_value("/test/device001/message", "/", 3) AS a FROM demo;
-- Output: {"a": "message"}STARTSWITH
startswith(col1, col2)Returns true if col1 starts with col2; otherwise returns false.
SUBSTRING
substring(col, start, length)Returns a substring starting at zero-based index start with a character length of length.
TRIM
trim(col)Removes leading and trailing whitespace characters from the string.
UPPER
upper(col)Converts all characters in the string to uppercase.
FORMAT
format(number, decimals [, locale])Formats numeric value number to a string rounded to decimals decimal places using optional locale conventions:
SELECT format(12332.1234567, 4, "en_US");
-- Output: '12,332.1235'Examples for 123456.78:
| Locale | Output Format |
|---|---|
en_US | 123,456.78 |
de_DE | 123.456,78 |
de_CH | 123'456.78 |
Supported regional locales include ar_AE, ar_SA, de_DE, en_AU, en_GB, en_IN, en_US, es_ES, es_MX, fr_FR, it_IT, ja_JP, ko_KR, nl_NL, pt_BR, ru_RU, zh_CN, and zh_TW.