Skip to main content

Introduction

The iff function evaluates a single Boolean predicate and returns one of two values depending on the result. Use it to add binary flag columns, choose between two computed expressions, or conditionally override a value in one step. The iif function is an alias for iff and behaves identically. For three or more branches, use case instead.

For users of other query languages

If you come from other query languages, this section explains how to adjust your existing queries to achieve the same results in APL.
Splunk SPL uses if(condition, value_if_true, value_if_false) inside an eval command. APL’s iff takes the same three arguments in the same order.
SQL Server provides IIF(condition, value_if_true, value_if_false), which maps directly to APL’s iff. In ANSI SQL you can also write CASE WHEN condition THEN value_if_true ELSE value_if_false END, which is equivalent.

Usage

Syntax

Parameters

Returns

The value of ifTrue when predicate evaluates to true, or ifFalse otherwise.
To return a null value from iff, use dynamic(null).

Use case examples

Flag requests that take longer than one second to identify slow endpoints.Query
Run in PlaygroundOutputThe query adds a is_slow column to each request and then counts how many fall into each category.
  • case: Multi-branch conditional that evaluates a list of conditions and returns the first matching result. Use case when you have three or more outcomes.
  • coalesce: Returns the first non-null value from a list of expressions. Use coalesce when you want to fall back from null rather than branch on a condition.