bin function to round values down to the nearest multiple of a specified bin size. This function is essential for grouping continuous data into discrete intervals, making it invaluable for time-based aggregations, histogram creation, and data bucketing.
The bin function works with numbers, dates, and timespans. When combined with the summarize operator, it enables powerful time-series analysis by grouping events into fixed intervals.
For users of other query languages
If you come from other query languages, this section explains how to adjust your existing queries to achieve the same results in APL.Splunk SPL users
Splunk SPL users
In Splunk SPL, you use the
bin command (formerly bucket) to group continuous values. APL’s bin function works similarly but is used as a scalar function within expressions.ANSI SQL users
ANSI SQL users
In ANSI SQL, you typically use
FLOOR with division and multiplication to achieve binning. APL’s bin function provides this capability directly.Usage
Syntax
Parameters
| Name | Type | Description |
|---|---|---|
value | real, datetime, or timespan | The value to round down to the nearest bin boundary. |
bin_size | real, datetime, or timespan | The size of each bin. Must be a positive value. |
Returns
The nearest multiple ofbin_size that is less than or equal to value. The return type matches the input type.
Use case examples
- Log analysis
- OpenTelemetry traces
Aggregate HTTP requests into 5-minute intervals to analyze traffic patterns.QueryRun in PlaygroundOutput
This query groups all HTTP requests into 5-minute windows, providing a time-series view of traffic volume and average response times.
| request_count | avg_duration |
|---|---|
| 581,330 | 0.8631ms |
List of related functions
- bin_auto: Automatically determines bin size based on the query time range. Use
binwhen you need explicit control over the bin size. - floor: Rounds down to the largest integer less than or equal to the input. Use
binfor rounding to arbitrary multiples. - ceiling: Rounds up to the smallest integer greater than or equal to the input. Use
binwhen you need to round down to specific intervals. - summarize: The
binfunction is commonly used withinsummarizefor time-based aggregations.