---
title: "Operations reference"
canonical: "https://docs.devo.com/space/latest/95191444/Operations%20reference"
format: markdown
---
> Macro (toc)

See the following table for a complete list of operations you can perform in the Devo platform to transform your data and get the required results. Remember that you can apply operations to your data [using the tools in the search window](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94764977) or write them directly in your query script [using LINQ](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95191261).

## How to use this reference

Each operation in the table includes the following information:

- **Operation name** - Click the name of any operation to learn how to apply it using the search window interface and how to write it using LINQ, as well as further examples and details, such as required input data types and output data types in case of **Aggregation** and **Create field** operations.
- **Description** - Brief definition of the operation and the expected results. In the Devo search window, operations are classified into **Aggregation** (using the `group every...` and `select... as...` commands in LINQ), **Filter **(using the `where...` command in LINQ) and **Create field** operations (using the `select... as...` command in LINQ). If an operation belongs to more than one type, you will see a description for each one.
- **Valid formats** - See the possible ways of applying each operation using LINQ (number of arguments, different operators...) and required input data types. The resulting output data type is also shown. Note that it only applies to **Create field** and **Aggregation** operations, since **Filter** operations do not add additional fields.

> ℹ️ **Null as a value**
> ℹ️ 
> ℹ️ When using operations with fields that contain null values, pay special attention to the way those null values are considered. In some cases it is considered as any other value in the field, while in some others it is simply considered as null and will not be computed.
> ℹ️ 
> ℹ️ For example, in operations such as *starts with (startswith)* or *ends with (endswith)*, it will be considered as null and not as a value. You can easily see this when using these operations to create boolean columns, where the result will be null instead of true or false.
> ℹ️ 
> ℹ️ If you need null values to be computed in such operations, we recommend using other operations before, such as *is null (isnull)* or *conditional (ifthenelse),* to transform them into other values you can use for the intended purpose.

## Operations list

Operations are ordered alphabetically in the tables below:

> Macro (rw-ui-tabs-macro)
> 
> > Macro (rw-tab)
> 
> | **Operation name** | **Description** | **Valid formats** |
> | --- | --- | --- |
> | [Absolute URI](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201791) | **Filter** - Retrieves only absolute URIs from a specified field.<br>**Create field** - Creates a Boolean field that shows *true* if a given URI is absolute. | `absoluteuri(string)`**  **`→`**  **`boolean` |
> | [Absolute value](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193179) | **Create field** - Adds a new field that returns the non-negative values of the numbers in a numeric field. | `abs(number)`**  **`→`**  **`number` |
> | [Addition, sum, plus / Concatenation](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193212) | **Create field** - Adds a new field that returns the addition or concatenation of the elements in the given fields.<br>Depending on the input data types, this operation retrieves different results. See the [operation article](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193212) for more details. | `number1 + number2 +... → number`<br>`duration1 + duration2 +... → duration`<br>`timestamp + duration → timestamp`<br>`string1 + string2 +... → string`<br>`tuple1 + tuple2 +... → tuple`<br>`add(number1, number2,...) → number`<br>`add(duration1, duration2,...) → duration`<br>`add(timestamp, duration) → timestamp`<br>`add(string1, string2,...) → string`<br>`add(tuple1, tuple2,...) → tuple` |
> | [And](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198111) | **Filter** - Retrieves those events where all the given Boolean field values are *true*.<br>**Create field** - Creates a Boolean field that returns *true* only if all the given arguments are *true*. | `boolean1 and boolean2 and ... → boolean` |
> | [Any name matches](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199143) | **Filter** - Filters a field containing sets of names in *set(name)* format* *and shows only those values that match one or more of the specified patterns.<br>**Create field** - Creates a new Boolean field that shows *true* when the values in a *set(name) *field match one or more of the specified patterns.<br>Learn more about the *set(name)* and *namepattern* data types in the [operation article](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199143). | `anymatches(setname, nameglob(string)) → boolean`<br>`anymatches(setname, namepattern) → boolean` |
> | [Approximated estimation](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200452) | **Create field** - Computes the approximated estimation of a set of distinct counts in *dc* data type.<br>Learn more about the *dc* data type in the [operation article](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200452). | `estimation(dc) → float` |
> | [Arc cosine](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198213) | **Create field** - Adds a new field that returns the arc cosine of the values of a numeric field. | `acos(number) → float` |
> | [Arc sine](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198253) | **Create field** - Adds a new field that returns the arc sine of the values of a numeric field. | `asin(number) → float` |
> | [Arc tangent](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198293) | **Create field** - Creates a new field that returns the arc tangent of the values of a numeric field. When applied with two arguments, it returns the arc tangent of the specified x- and y-coordinates. | `atan(number) → float`<br>`atan(number1, number2) → float` |
> | [At](https://devodocs.atlassian.net/wiki/spaces/latest/pages/389152771) | **Create field **- Returns the n-th element of a tuple. | `at(tuple, n)`<br>`(tuple)[n]` |
> | [At (at0)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/617742361) | **Create field **- Returns the first element of a tuple. | `at0(tuple) → string` |
> | [At (at1)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/617840641) | **Create field **- Returns the second element of a tuple. | `at1(tuple) → string` |
> | [At (atend)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/617775107) | **Create field **- Returns the second element of a tuple. | `atend(tuple) → string` |
> | [Average](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192134) | **Aggregation** - Calculates the average of the grouped values of the selected numeric field. | `avg(number) → number` |
> | [Bag](https://devodocs.atlassian.net/wiki/spaces/latest/pages/388890645) | **Create field - **Creates a new field with the mapped elements of a given array and their count. | `bag([array1, array3, array2, array6, array5, array4, array7]) === {array1:number, array2:number, array3:number, array4:number, array5:number, array6:number, array7:number}` |
> | [Band](https://devodocs.atlassian.net/wiki/pages/createpage.action?spaceKey=latest&title=Band%20%28band%29&linkCreation=true&fromPageId=95191444) | **Create field - **Creates a new field that returns the intersection of two sets or maps. This operation is called **Intersection **when executed on the **Set **and **Map **data types. For any other data types, see the [Bitwise And (band)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198338) operation. | `band(set1, set2) → integer`<br>`band(map1, map2) → integer` |
> | [Bitwise AND](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198338) | **Create field** - Creates a new field that retrieves the [Bitwise AND](https://en.wikipedia.org/wiki/Bitwise_operation#AND) of the specified arguments. | `band(integer1, integer2) → integer`<br>`integer1 & integer2 → integer` |
> | [Bitwise left shift](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198375) | **Create field** - Creates a new field that shifts to the left the bits of the values in the first argument as many positions as specified in the second argument. | `lshift(integer1, integer2) → integer`<br>`integer1 << integer2 → integer` |
> | [Bitwise NOT](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198417) | **Create field** - Creates a new field that retrieves the [Bitwise NOT](https://en.wikipedia.org/wiki/Bitwise_operation#NOT) of the specified argument. | `bnot(integer) → integer`<br>`~(integer) → integer` |
> | [Bitwise OR](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198456) | **Create field** - Creates a new field that retrieves the [Bitwise OR](https://en.wikipedia.org/wiki/Bitwise_operation#OR) of the specified arguments. | `bor(integer1, integer2) → integer`<br>`integer1 | integer2 → integer` |
> | [Bitwise right shift](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198493) | **Create field** - Creates a new field that shifts to the right the bits of the values in the first argument as many positions as specified in the second argument.<br>This operation keeps the sign bit intact, so the sign of the original number is always preserved. Use [Bitwise unsigned right shift (urshift, >>>)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198539) if you don't want to preserve the sign bit. | `rshift(integer1, integer2) → integer`<br>`integer1 >> integer2 → integer` |
> | [Bitwise unsigned right shift](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198539) | **Create field** - Creates a new field that shifts to the right the bits of the values in the first argument as many positions as specified in the second argument.<br>This operation always fills vacant places after shifting with zeros, so the sign of the original number may vary. Use [Bitwise right shift (rshift, >>)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198493) if you want to preserve the sign of the original number. | `urshift(integer1, integer2) → integer`<br>`integer1 >>> integer2 → integer` |
> | [Bitwise XOR](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198578) | **Create field** - Creates a new field that retrieves the [Bitwise XOR](https://en.wikipedia.org/wiki/Bitwise_operation#XOR) of the specified arguments. | `bxor(integer1, integer2) → integer`<br>`integer1 ^ integer2 → integer` |
> 
> > Macro (rw-tab)
> 
> | **Operation name** | **Description** | **Valid formats** |
> | --- | --- | --- |
> | [Ceiling](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193240) | **Create field** - Adds a new field that rounds the values of a numeric field, returning the smallest following integer numbers.<br>Use [Floor (floor)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193382) if you want to get the largest previous integers. | `ceil(number) → number` |
> | [Collect](https://devodocs.atlassian.net/wiki/spaces/latest/pages/446136323) | **Create field - **Creates a new field** **collecting given elements into an array, following the order of aggregated events. | `collect(number) → array` |
> | [Collect compact](https://devodocs.atlassian.net/wiki/spaces/latest/pages/445906974) | **Create field - **Creates a new field collecting given elements into a map, following the order of aggregated events. | `collectcompact(number) → map   ` |
> | [Collect distinct](https://devodocs.atlassian.net/wiki/spaces/latest/pages/446234632) | **Create field - **Creates a new field collecting given elements into a set, following the order of aggregated events. | `collectdistinct(number) → set ` |
> | [Collect sorted](https://devodocs.atlassian.net/wiki/spaces/latest/pages/445906951) | **Create field - **Creates a new field collecting** **a given grouping of floats into an sorted array. | `collectsorted(number) → array ` |
> | [Conditional](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195787) | **Create field** - Adds a new field that returns the second argument if the field given as first argument (must be a Boolean field) shows *true*, and the third argument if it shows *false*. | `ifthenelse(boolean, value1_true, value2_false) → value` |
> | [Contains](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200521) | **Filter** - Checks for the presence of one or more values in a given string. The filter will identify those strings containing at least one of the indicated values.<br>**Create field** - Creates a Boolean field that shows *true* when at least one of the indicated values is present in the given string.<br>If you enter your query using LINQ, note that the` ->` operator syntax does not admit more than two arguments. Use the `has()` syntax if you need to add more than one value.<br>This operation is case sensitive. Use the [Contains - case insensitive (weakhas)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200553) operation if you need to apply this filter ignoring case. | `string_general -> string_value → boolean`<br>`has(string_general, string_value1, string_value2...) → boolean` |
> | [Contains - case insensitive](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200585) | **Filter** - Returns only those strings that contain a specified value, ignoring case.<br>**Create field** - Creates a Boolean field that shows *true* when the indicated value is present in the given string, ignoring case.<br>Use the [Contains (has, ->)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200521) operation if you need to discriminate between uppercase and lowercase letters. | `weakhas(string_general, string_value) → boolean` |
> | [Contains tokens](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200622) | **Filter** - Returns only those strings including a specific token. Optionally, you can add one or two boolean values to extend the left and right length of the token.<br>**Create field** - Adds a new Boolean field that shows *true *when a specific token is present in a given string. Optionally, you can add one or two boolean values to extend the left and right length of the token. | `toktains(string1, string2) → boolean`<br>`toktains(string1, string2, boolean_left) → boolean`<br>`toktains(string1, string2, boolean_left, boolean_right) → boolean` |
> | [Contains tokens - case insensitive (weaktoktains)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200585) | **Filter** - Returns only those strings including a specific token, ignoring case. Optionally, you can add one or two boolean values to extend the left and right length of the token.<br>**Create field **- Adds a new Boolean field that shows *true *when a specific token is present in a given string, ignoring case. Optionally, you can add one or two boolean values to extend the left and right length of the token. | `weaktoktains(string1, string2)`<br>`weaktoktains(string1, string2, boolean_left)`<br>`weaktoktains(string1, string2, boolean_left, boolean_right)` |
> | [Coordinates distance](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195957) | **Create field** - Adds a new field that returns the distance in meters between two geocoords. | `distance(geocoord1, geocoord2) → float`<br>`distance(geocoord(string1), geocoord(string2)) → float`<br>`distance(latlon(string1), latlon(string2)) → float` |
> | [Cosine](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198615) | **Create field** - Adds a new field that returns the cosine of the values of a numeric field. | `cos(number) → float` |
> | [Count](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192168) | **Aggregation** - Returns either the number of events in each group (if you add no arguments) or the number of non-null values in each group (if you add an argument). | `count() → integer`<br>`count(number) → integer` |
> | [Cube root](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193275) | **Create field** - Adds a new field that returns the cube root of the values of a given numeric field. | `cbrt(number) → number` |
> | [Day / day of the month](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195038) | **Create field** - Returns the duration representation of 1 day (*1d*), or the day of the month from a given timestamp. Optionally, you can add a timezone different than your current one. | `day() → 1d`<br>`day(timestamp) → integer`<br>`day(timestamp, timezone_string) → integer` |
> | [Day name](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195072) | **Create field** - Returns the name of the day from a given timestamp. Optionally, you can check it in a time zone different than yours and specify the language in which the day name will appear (en by default). | `dayname(timestamp)`  →  `integer`<br>`dayname(timestamp, locale_string) `→  `string`<br>`dayname(timestamp, locale_string, timezone_string)`  →  `string` |
> | [Day number](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195114) | **Create field** - Returns the number of the day in the month from a given timestamp. This count starts from 1, differing from the [Day of the month](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195038) operation, which starts from 0. Optionally, you can check it in a time zone different than yours. | `daynumber(timestamp)`  → `integer`<br>`daynumber(timestamp, timezone_string)`  →`integer` |
> | [Day of the week](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195141) | **Create field** - Returns the day of the week from a given timestamp. Optionally, you can add a timezone different than your current one. | `dayofweek(timestamp) → integer`<br>`dayofweek(timestamp, timezone_string) → integer` |
> | [Day of the year](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195175) | **Create field** - Returns the day of the year from a given timestamp. Optionally, you can add a timezone different than your current one. | `dayofyear(timestamp) → integer`<br>`dayofyear(timestamp, timezone_string) → integer` |
> | [Decode, switch](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195822) | **Create field** - Conditional operation that evaluates the values in a specified field, verifies if they match a specified value and transform them into a different value in case they do. You can also set an additional value that will be returned when the values don't match.<br>This operation is a conditional control flow statement, but unlike the [Conditional (ifthenelse)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195787) operation, multiple execution paths are allowed. | `decode(when_field, is_value, transform_to_value)`<br>`decode(when_field, is_value, transform_to_value, otherwise_value)`<br>`decode(when_field, is_value, transform_to_value, is_value2, transform_to_value2...)` |
> | [Division](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193308) | **Create field** - The new field returns the division of two numbers or the division of a duration and an integer number.<br>When both numbers are integer and the division is not exact, the result will be the value of the quotient. | `number1 \ number2 → integer`<br>`div(number1, number2) → integer`<br>`duration \ integer → duration`<br>`div(duration, integer) → duration` |
> | [Division remainder](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193343) | **Create field** - Adds a new field that returns the remainder of the division of the integer values in a field by another field or value.<br>The [Modulo (mod, %%)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193417) operation also returns the remainder of a division, but applies a different formula to calculate it. Go to the operation article to learn more. | `rem(integer1, integer2) → integer`<br>`integer1 % integer2 → integer` |
> | [Drop nulls](https://devodocs.atlassian.net/wiki/spaces/latest/pages/388923414) | **Create field - **Creates a new field with the the nulls removed  from a given array. | `dropnulls([array1,null,array2,null,array3,null,array4]) → array  ` |
> | [Duration](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193691) | **Create field** -  Adds a new field that transforms a string representing an amount of time into *duration* type.<br>The input string must follow a specific format to be transformed. Learn more in the operation article. | `duration(string) → duration` |
> 
> > Macro (rw-tab)
> 
> | **Operation name** | **Description** | **Valid formats** |
> | --- | --- | --- |
> | [e (mathematical constant)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198650) | **Create field** - Adds a new field that returns the value of the Euler's number (2.718281828459045). | `e()` |
> | [Edit distance: Damerau](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200657) | **Create field** - Creates a new field that returns the Damerau edit distance between two strings. | `damerau(string1, string2) → integer` |
> | [Edit distance: Hamming](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200687) | **Create field** - Creates a new field that returns the Hamming edit distance between two strings. | `hamming(string1, string2) → integer` |
> | [Edit distance: Levenshtein](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200717) | **Create field** - Creates a new field that returns the Levenshtein edit distance between two strings. | `levenshtein(string1, string2) → integer` |
> | [Edit distance: OSA](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200747) | **Create field** - Creates a new field that returns the OSA edit distance between two strings. | `osa(string1, string2) → integer` |
> | [Ends with](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200777) | **Filter** - Filters string values that end with a specified suffix.<br>**Create field** - Creates a Boolean field that shows *true *for those strings that end with a specified suffix. | `endswith(string1, string2_suffix) → boolean` |
> | [Epoch milliseconds](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195209) | **Create field** - Creates a new field that converts a specified timestamp into an epoch reference date: number of milliseconds since midnight Jan 1, 1970.  
> See also the [Timestamp (timestamp)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194177) function, which transforms epoch dates or strings representing dates into timestamps. | `epoch(timestamp) → integer`<br>`epoch(timestamp(string)) → integer`<br>`epoch(timestamp(integer)) → integer` |
> | [Equal](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199544) | **Filter** - Compares two values of the same type and returns only the events where both values are exactly the same.<br>**Create field** - Creates a Boolean field that shows *true* when two values are exactly the same.<br>This operation is case sensitive. Use [Equal - case insensitive (eqic)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199574) if you need to apply this operation ignoring case. | `field1 = field2 → boolean`<br>`eq(field1, field2) → boolean` |
> | [Equal - case insensitive](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199574) | **Filter** - Compares if two strings are the same. It returns only the rows where both values are the same, ignoring case.<br>**Create field** - Creates a Boolean field that shows *true* when two strings are exactly the same, ignoring case.<br>Use the [Equal (eq, =)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199544) operation if you need to discriminate between uppercase and lowercase letters. | `eqic(string1, string2) → boolean` |
> | [Ethernet destination MAC address](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199759) | **Create field** - Returns the destination MAC address of an Ethernet frame. | `etherdst(packet) → mac` |
> | [Ethernet payload](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199775) | **Create field** - Returns the payload of an Ethernet frame. | `etherpayload(packet) → boxar(int1)` |
> | [Ethernet source MAC address](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199791) | **Create field** - Returns the source MAC address of an Ethernet frame. | `ethersrc(packet) → mac` |
> | [Ethernet status](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199807) | **Create field** - Returns the status of an Ethernet packet. | `etherstatus(packet) → string` |
> | [Ethernet tag](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199823) | **Create field** - Returns the tag of an Ethernet Frame. | `ethertag(packet) → string` |
> | [EtherType](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199839) | **Create field** - Returns the EtherType of the Ethernet frame of a packet. | `ethertype(packet) → integer` |
> | [Exponential: base e](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198680) | **Create field** - Returns the value of the constant e to the power of the values in a specified field. | `exp(number) → float` |
> | [First](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192210) | **Aggregation** - Returns the first value of a specified field for each group. | `first(field) → value` |
> | [First not null](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192244) | **Aggregation** - Returns the first non-null value of a specified field for each group. | `nnfirst(field) → value` |
> | [Floor](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193382) | **Create field** - Rounds the values of a numeric field, returning the largest previous integer values in the new field.<br>Use [Ceiling (ceil)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193240) if you want to get the smallest following integers. | `floor(number) → number` |
> | [Format date](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193724) | **Create field** - Format a given timestamp using a custom format, optionally specifying a different time zone and a locale. | `formatdate(timestamp, string_format) → timestamp`<br>`formatdate(timestamp, string_format, string_timezone) → timestamp`<br>`formatdate(timestamp, string_format, string_timezone, string_locale) → timestamp` |
> | [Format number](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200810) | **Create field** - Converts a number according to a format and an optional locale. It is used to separate the digits following the specified format. The result will be a new field containing the strings formatted as specified, depending on the locale (if set).<br>See the [operation article](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200810) for the syntax accepted for the format pattern and the locale. | `formatnumber(number, string_format) → string`<br>`formatnumber(number, string_format, string_locale) → string` |
> | [From base16, b16, hex](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193801) | **Create field** - Creates a byte array from a valid hexadecimal (base16) string. | `from16(hex_string) → boxar(int1)` |
> | [From base16](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193773) | **Create field** - creates an integer from a valid hexadecimal (base16) string. | `hex8(string) → integer` |
> | [From base64, b16 ](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193838) | **Create field** - Creates a byte array from a valid base64 string. | `from64(base64_string) → boxar(int1)` |
> | [From UTF8](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193875) | **Create field** - Returns an UTF8 string from the given byte array. | `fromutf8(boxar(int1`*)*`) → string`<br>`fromutf8(from16`**(**`string`**)**`) → string`<br>`fromutf8(mkboxar`**(**`integer`**)**`) → string` |
> | [From Z85, base85 ](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193924) | **Create field** - Creates a byte array from a valid Z85 string. | `fromz85(Z85_string) → boxar(int1)` |
> 
> > Macro (rw-tab)
> 
> | **Operation name** | **Description** | **Valid formats** |
> | --- | --- | --- |
> | [Geocoord](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95196035) | **Create field** - Generates a geocoord from the given string, which must be either the representation of sexagesimal coordinates, using degrees, minutes, seconds and position (for example 40°24'46.3"N 3°41'43.8"W) or a hash representation of coordinates (for example *ezjmguvj*) | `geocoord(string) → geocoord` |
> | [Geographic coordinate system](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195991) | **Create field** - Returns the coordinate system of a given geocoord. | `coordsystem(geocoord) → string`<br>`coordsystem(geocoord(string)) → string` |
> | [Geohash](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95196073) | **Create field** - Generates a geohash from a given geocoord, or converts a string representing a geohash to geohash format. If you enter a geocoord as input, you can optionally select the size of the output geohash. | `geohash(string) → geocoord`<br>`geohash(geocoord) → geocoord`<br>`geohash(geocoord, size_integer) → geocoord`<br>`geohash(geocoord(string) → geocoord`<br>`geohash(geocoord(string), size_integer) → geocoord` |
> | [Geohash string](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95196126) | **Create field** - Transforms a given geohash in *geocoord* data type into *string* data type. You can optionally select the size of the output string. | `geohashstr(geocoord) → string`<br>`geohashstr(geocoord, size_integer) → string` |
> | [Geolocated Accuracy Radius](https://docs.devo.com/space/latest/95196240) | **Create field** - Geolocates an IPv4 or IPv6 address and returns the accuracy radius, in km, around the latitude and longitude with a 67% confidence, using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `accuracyradius(ip) → float`<br>`accuracyradius(ip6) → float` |
> | [Geolocated AS Organization Name](https://docs.devo.com/space/latest/95196162/Geolocated+AS+Organization+Name+(asorg)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns the organization associated with the registered autonomous system number or owner name, using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `asorg(ip) → string`<br>`asorg(ip6) → string` |
> | [Geolocated ASN](https://docs.devo.com/space/latest/95196318/Geolocated+ASN+(asn)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns the autonomous system number, using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `asn(ip) → integer`<br>`asn(ip6) → integer` |
> | [Geolocated City ](https://docs.devo.com/space/latest/95196416/Geolocated+City+(city)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns the corresponding city name, using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `city(ip) → string`<br>`city(ip6) → string` |
> | [Geolocated connection type](https://docs.devo.com/space/latest/95196492/Geolocated+connection+type+(connectiontype)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns the connection type, using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. The possible connection type values are *Dialup*, *Cable/DSL*, *Corporate* or *Cellular*. | `connectiontype(ip) → string`<br>`connectiontype(ip6) → string` |
> | [Geolocated coordinates](https://docs.devo.com/space/latest/95196573/Geolocated+coordinates+(coordinates)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns its coordinates, using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `coordinates(ip) → geocoord`<br>`coordinates(ip6) → geocoord` |
> | [Geolocated Country](https://docs.devo.com/space/latest/95196649/Geolocated+Country+(countrycode)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns the corresponding country name (as a two-character [ISO 3166-1](https://en.wikipedia.org/wiki/ISO_3166-1) code), using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `countrycode(ip) → string`<br>`countrycode(ip6) → string` |
> | [Geolocated ISP name](https://docs.devo.com/space/latest/95196727/Geolocated+ISP+name+(isp)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns its ISP name (Internet Server Provider), using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `isp(ip) → string`<br>`isp(ip6) → string` |
> | [Geolocated Latitude](https://docs.devo.com/space/latest/95196803/Geolocated+Latitude+(latitude)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns the approximate latitude, using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `latitude(ip) → string`<br>`latitude(ip6) → string` |
> | [Geolocated Level 1 Subdivision](https://docs.devo.com/space/latest/95196843/Geolocated+Level+1+Subdivision+(subdivision1code)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns the level 1 subdivision or region name using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `subdivision1code(ip) → string`<br>`subdivision1code(ip6) → string` |
> | [Geolocated Level 2 Subdivision ](https://docs.devo.com/space/latest/95196887/Geolocated+Level+2+Subdivision+(subdivision2code)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns the level 2 subdivision or region name using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `subdivision2code(ip) → string`<br>`subdivision2code(ip6) → string` |
> | [Geolocated Longitude](https://docs.devo.com/space/latest/95196971/Geolocated+Longitude+(longitude)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns the approximate longitude, using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `longitude(ip) → float`<br>`longitude(ip6) → float` |
> | [Geolocated organization name ](https://docs.devo.com/space/latest/95197041/Geolocated+organization+name+(org)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns the organization name, using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `org(ip) → string`<br>`org(ip6) → string` |
> | [Geolocated Postal Code](https://docs.devo.com/space/latest/95197103/Geolocated+Postal+Code+(postalcode)) | **Create field** - Geolocates an IPv4 or IPv6 address and returns the postal code, using [MaxMind](https://www.maxmind.com/en/home) IP geolocation. | `postalcode(ip) → string`<br>`postalcode(ip6) → string` |
> | [Glob pattern on names](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199125) | **Create field** - Creates a glob pattern on names (*namepattern* data type). Glob patterns specify sets of filenames with wildcard characters and are required when using the [Any name matches](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199143) operation | `nameglob(string) → namepattern` |
> | [Greater or equal](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199604) | **Filter** - Filters those events where a value is greater than or equal to either another field of the same data type or a specified value.<br>**Create field** - Creates a Boolean field that shows *true* when a value is greater than or equal to either another field of the same data type or a specified value. | `value1 >= value2 → boolean`<br>`ge(value1, value2) → boolean` |
> | [Greater than](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199634) | **Filter** - Filters those events where a value is greater than either another field of the same data type or a specified value.<br>**Create field** - Creates a Boolean field that shows *true* when a value is greater than either another field of the same data type or a specified value. | `value1 > value2 → boolean`<br>`gt(value1, value2) → boolean` |
> | [Has Ethernet frame](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199855) | **Create field** - Creates a Boolean field that shows *true* if a specified packet has an Ethernet frame. | `hasether(packet) → boolean` |
> | [Has IPv4 datagram](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199871) | **Create field** - Creates a Boolean field that shows *true* if a specified packet has an IPv4 datagram. | `hasip4(packet) → boolean` |
> | [Has TCP segment](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199887) | **Create field** - Creates a Boolean field that shows *true* if a specified packet has a TCP segment. | `hastcp(packet) → boolean` |
> | [Has UDP datagram](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199903) | **Create field** - Creates a Boolean field that shows *true* if a specified packet has a UDP datagram. | `hasudp(packet) → boolean` |
> | [Hostname public suffix](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200838) | **Create field** - Extracts the[ public suffix](https://publicsuffix.org/) from the hostnames in a given string field. * * | `publicsuffix(string) → string` |
> | [Hostname root domain](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200873) | **Create field** - Extracts the root domain from the hostnames in a given string field. | `rootdomain(string) → string` |
> | [Hostname root prefix](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200908) | **Create field** - Extract the root prefix from the hostnames in a given string field. A root prefix includes everything that comes before the root domain, including it. | `rootprefix(string) → string` |
> | [Hostname root suffix](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200943) | **Create field** - Extract the root suffix from the hostnames in a given string field. A root suffix includes everything that comes after the root domain, including it. | `rootsuffix(string) → string` |
> | [Hostname subdomains](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200978) | **Create field** - Extract the [subdomain ](https://en.wikipedia.org/wiki/Subdomain)from the hostnames in a given string field. | `subdomain(string) → string` |
> | [Hostname top level domain](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201017) | **Create field** - Extracts the [top-level domain](https://en.wikipedia.org/wiki/Top-level_domain) (TLD) from the hostnames in a given string field. | `topleveldomain(string) → string` |
> | [Hour](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195241) | **Create field** - Returns the duration representation of 1 hour, or the hours corresponding to a given timestamp. Optionally, you can add a timezone different than your current one. | `hour() → 1h`<br>`hour(timestamp) → duration`<br>`hour(timestamp, timezone_string) → duration` |
> | [HTTP Status Description](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199184) | **Create field** - Returns the HTTP status description from a given HTTP status code. | `httpstatusdescription(integer) → string` |
> | [HTTP Status Type](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199212) | **Create field** - Returns the HTTP status type from a given HTTP status code. | `httpstatustype(integer) → string` |
> | [Human size](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193961) | **Create field** - Converts a number into a human-readable format, using a binary prefix by default. Optionally, you can add a second boolean argument to specify the required format (*true* is for binary prefix (2x) and *false* for decimal prefix (10x). | `humanSize(integer) → string`<br>`humanSize(integer, boolean) → string` |
> | [Hyperbolic cosine](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198750) | **Create field** - Returns the hyperbolic cosine of the specified number. | `cosh(number) → float` |
> | [Hyperbolic sine](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198750) | **Create field** - Returns the hyperbolic sine of the specified number. | `sinh(number) → float` |
> | [Hyperbolic tangent](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198785) | **Create field** - Returns the hyperbolic tangent of the specified number. | `tanh(number) → float` |
> | [HyperLogLog++](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192278) | **Aggregation** - Applies the [HyperLogLog++](https://en.wikipedia.org/wiki/HyperLogLog#HLL++) algorithm to the groups of a specified field, which is used to calculate the estimated count of distinct elements in each group. The output data type is *dc* (distinct count).<br>This operation returns the same results as the [HyperLogLog++ Count Estimation (hllppcount)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192326) operation, the only difference is the output data type. | `hllpp(field) → dc` |
> | [HyperLogLog++ Count Estimation](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192326) | **Aggregation** - Applies the [HyperLogLog++](https://en.wikipedia.org/wiki/HyperLogLog#HLL++) algorithm to the groups of a specified field, which is used to calculate the estimated count of distinct elements in each group. The output data type is *float.*<br>This operation returns the same results as the [HyperLogLog++](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192278) operation, the only difference is the output data type. | `hllppcount(field) → float` |
> | [HyperLogLog++ pack](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200482) | **Create field** - Transforms a byte array of data type *dc* to a hexadecimal string of data type *boxar(int1)* | `pack(dc) → boxar(int1)` |
> | [HyperLogLog++ unpack](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200498) | **Create field** - Transforms a hexadecimal string of data type *boxar(int1) *into a byte array of data type *dc*. | `unpackhllpp(boxar(int1)) → dc` |
> 
> > Macro (rw-tab)
> 
> | **Operation name** | **Description** | **Valid formats** |
> | --- | --- | --- |
> | [Index of](https://devodocs.atlassian.net/wiki/spaces/latest/pages/388890626) | **Create field - **Creates a new field** **extracting the index of the first occurrence of a given value in an array. If no index is found, the result will be -1. | `indexof(Array, "integer")  → array` |
> | [IP Protocol](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199240) | **Create field** - Converts an IP protocol name to its protocol code or vice versa. | `ipprotocol(protocol_name_string) → integer`<br>`ipprotocol(protocol_code_integer) → string` |
> | [IP Reputation Score](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199275) | **Create field** - Assigns a reputation score to an IPv4 address according to several IP reputation lists. | `reputationscore(ip) → integer` |
> | [IP Reputation Tags](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199303) | **Create field** - Labels an IPv4 address according to several IP reputation lists. | `reputation(ip) → string` |
> | [IPv4 destination address](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199919) | **Create field** - Returns the destination IPv4 address of a specified IPv4 datagram (*packet* data type). | `ip4dst(packet) → ip` |
> | [IPv4 differentiated services](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199935) | **Create field** - Returns the Differentiated Services Code Point (DSCP) of a specified IPv4 datagram (*packet* data type). | `ip4ds(packet) → integer` |
> | [IPv4 explicit congestion notification](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199951) | **Create field** - Returns the Explicit Congestion Notification (ECN) of a specified IPv4 datagram (*packet* data type). | `ip4ecn(packet) → integer` |
> | [IPv4 flags](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199967) | **Create field** - Returns the flag value of a specified IPv4 datagram (*packet* data type). | `ip4flags(packet) → integer` |
> | [IPv4 fragment offset](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199983) | **Create field** - Returns the fragment offset of a specified IPv4 datagram (*packet* data type). | `ip4fragment(packet) → integer` |
> | [IPv4 header checksum](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199999) | **Create field** - Returns the header of a specified IPv4 datagram (*packet* data type). | `ip4cs(packet) → integer` |
> | [IPv4 header length](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200015) | **Create field** - Returns the Internet header length (IHL) of a specified IPv4 datagram (*packet* data type). | `ip4hl(packet) → integer` |
> | [IPv4 identification](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200031) | **Create field** - Returns the identification field value of a specified IPv4 datagram (*packet* data type). | `ip4ident(packet) → integer` |
> | [IPv4 legal use](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199331) | **Create field** - Returns the purpose or legal use of the given IPv4 address. | `purpose(ip) → integer` |
> | [IPv4 payload](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200047) | **Create field** - Returns the payload of a specified IPv4 datagram (*packet* data type). | `ip4payload(packet) → boxar(int1)` |
> | [IPv4 protocol](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200063) | **Create field** - Returns the protocol field value of a specified IPv4 datagram (*packet* data type). | `ip4proto(packet) → integer` |
> | [IPv4 source address](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200079) | **Create field** - Returns the source IPv4 address of a specified IPv4 datagram (*packet* data type). | `ip4src(packet) → ip` |
> | [IPv4 status](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200095) | **Create field** - Returns the status of a specified IPv4 datagram (*packet* data type). | `ip4status(packet) → string` |
> | [IPv4 time to live](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200111) | **Create field** - Returns the time to live (TTL) value in seconds of a specified IPv4 datagram (*packet* data type). | `ip4ttl(packet) → integer` |
> | [IPv4 total length](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200127) | **Create field** - Returns the total length field value of a specified IPv4 datagram (*packet* data type). | `ip4len(packet) → integer` |
> | [IPv4 type of service](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200143) | **Create field** - Returns the type of service field value of a specified IPv4 datagram (*packet* data type). | `ip4tos(packet) → integer` |
> | [IPv6 host number ](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199359) | **Create field** - Returns the host number of an IPv6 address. | `host(ip6) → integer` |
> | [IPv6 routing number](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199389) | **Create field** - Returns the routing part of an IPv6 address. | `routing(ip6) → integer` |
> | [Is empty](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201054) | **Filter** - Checks if a given string is empty.<br>**Create field** - Adds a new Boolean field that shows *true *only for those strings that are empty. | `isempty(string) → boolean` |
> | [Is in](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201087) | **Filter** - Checks for the presence of one or more values in a given string. The filter will identify those strings containing at least one of the indicated values.<br>You can also use it to filter IPv4 addresses that belong to a specific net.<br>**Create field** - Adds a new Boolean field that shows *true *only for those strings that contain at least one of the indicated values.<br>You can also use it to create a new field that shows *true* for IPv4 addresses that belong to a specific net.<br>If you enter your query using LINQ, note that the `<-` operator syntax does not admit more than two arguments. Use the ``in`()` syntax if you need to add more than one value.<br>This operation is case sensitive. Use the [Is in - case insensitive (weakin)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201126) operation if you need to apply this filter ignoring case. | `where in (string) → boolean`<br>`select in (string) → boolean`<br>`where "value" <- boolean`<br>`select "value" <- boolean` |
> | [Is in - case insensitive](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201126) | **Filter** - Returns only those strings that contain a specified value, ignoring case.<br>**Create field** - Creates a Boolean field that shows *true *only for those strings that contain a specified value, ignoring case.<br>Use the [Is in (`in`, <-)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201087) operation if you need to discriminate between uppercase and lowercase letters. | `weakin(string_value, string_general) → boolean` |
> | [Is IPv4 ](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199419) | **Create field** - Creates a Boolean field that returns *true *if a specified IPv6 is carrying an IPv4. | `isip4(ip6) → boolean` |
> | [Is not null](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195894) | **Filter** - Filters non-null values in a given field.<br>**Create field** - Creates a Boolean field that shows *true* if a given value is not null. | `isnotnull(field) → boolean` |
> | [Is null](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195922) | **Filter** - Filters null values in a given field.<br>**Create field** - Creates a Boolean field that shows *true* if a given value is null. | `isnull(field) → boolean` |
> | [Is Private IPv4](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199449) | **Filter** - Returns only the private IP addresses of a selected *ip* field.<br>**Create field** - Creates a Boolean field that shows *true* if a given IP address is private. | `isprivate(ip) → boolean` |
> | [Is Public IPv4](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199477) | **Filter** - Returns only the public IP addresses of a selected *ip* field.<br>**Create field** - Creates a Boolean field that shows *true* if a given IP address is public. | `ispublic(ip) → boolean` |
> | [ISO-3166-1 Continent Alpha-2 Code](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197196) | **Create field** - Returns the ISO-3166-1 Continent Alpha-2 Code from any continent identification. | `continentalpha2(continent_string) → string` |
> | [ISO-3166-1 Continent Name](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197249) | **Create field** - Returns the ISO-3166-1 Continent Name from any continent identification. | `continentname(continent_string) → string` |
> | [ISO-3166-1 Country Alpha-2 Code](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197298) | **Create field** - Returns the ISO-3166-1 Country Alpha-2 Code from any country identification. | `countryalpha2(country_string) → string` |
> | [ISO-3166-1 Country Alpha-2 Continent](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197347) | **Create field** - Returns the ISO-3166-1 Country Alpha-2 Continent from any country identification. | `countrycontinent(country_string) → string` |
> | [ISO-3166-1 Country Alpha-3 Code](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197406) | **Create field** - Returns the ISO-3166-1 Country Alpha-3 Code from any country identification. | `countryalpha3(country_string) → string` |
> | [ISO-3166-1 Country Latitude](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197455) | **Create field** - Returns the ISO-3166-1 Country Latitude from any country identification. | `countrylatitude(country_string) → float` |
> | [ISO-3166-1 Country Longitude](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197504) | **Create field** - Returns the ISO-3166-1 Country Longitude from any country identification. | `countrylongitude(country_string) → float` |
> | [ISO-3166-1 Country Name](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197553) | **Create field** - Returns the ISO-3166-1 Country Name from any country identification. | `countryname(country_string) → string` |
> | [Jq evaluation](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198042) | **Create field** - Uses the jq JSON processor to identify and extract a single value from a JSON object contained in another field. | `jqeval(jqcompile(json_value), json) → json` |
> | [Jq filter compilation](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198077) | **Create field** - Compiles a jq filter to be used as an argument of the [Jq evaluation (jqeval)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198042) operation. | `jqcompile(string) → jq` |
> | [Join](https://devodocs.atlassian.net/wiki/spaces/latest/pages/388923425) | **Create field **- Creates a new field with the strings of a given array joined to form a single string. | `join(array) → array ` |
> | [Json value type](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197976) | **Create field** - Returns the type of the values in a JSON object. Note that you must first extract the part of the JSON you want to analyze using the [Jq evaluation (jqeval)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198042)** **operation. | `label(json_value) → string` |
> 
> > Macro (rw-tab)
> 
> | **Operation name** | **Description** | **Valid formats** |
> | --- | --- | --- |
> | [Keys](https://devodocs.atlassian.net/wiki/spaces/latest/pages/388825112) | **Create field - **Creates a new field** **returning the set of keys of a given map. | `keys(map) → map ` |
> | [Last](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192362) | **Aggregation** - Returns the last value of the selected field for each group. | `last(field) → value` |
> | [Last not null](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192396) | **Aggregation** - Returns the last non-null value of the selected field for each group. | `nnlast(field) → value` |
> | [Latitude](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197602) | **Create field** - Returns the latitude of a given geocoord. | `latitude(geocoord) → float` |
> | [Latitude and longitude coordinates](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197664) | **Create field** - Generates a geocoord based on sexagesimal coordinates. It can be done using latitude and longitude numerical values, another geocoord or a string representing coordinates. | `latlon(latitude_float, longitude_float) → geocoord`<br>`latlon(geocoord) → geocoord`<br>`latlon(coordinates_string) → geocoord` |
> | [Leap year](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195285) | **Create field** - Checks if the year corresponding to a given timestamp is a leap year or not. Optionally, you can check it in a timezone different than yours. | `isleapyear(timestamp)` → `string`<br>`isleapyear(timestamp, timezone_string)` → `string` |
> | [Length](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201158) | **Create field** - Adds a new field that returns the length of a string. | `length(string) → integer` |
> | [Less or equal](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199664) | **Filter** - Filters those events where a value is less than or equal to either another field of the same data type or a specified value.<br>**Create field** - Creates a Boolean field that shows *true* when a value is less than or equal to either another field of the same data type or a specified value. | `value1 <= value2 → boolean`<br>`le(value1, value2) → boolean` |
> | [Less than](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199694) | **Filter** - Filters those events where a value is less than either another field of the same data type or a specified value.<br>**Create field** - Creates a Boolean field that shows *true* when a value is less than either another field of the same data type or a specified value. | `value1 < value2 → boolean`<br>`lt(value1, value2) → boolean` |
> | [Locate](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201186) | **Create field** - The field created returns the position of the first occurrence of a specified value in a string, counting from 0. Note that this operation is case sensitive. | `locate(string, string_to_locate) → integer` |
> | [Logarithm: base 10](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198864) | **Create field** - Returns the base-10 logarithm of the selected number. | `log10(number) → float` |
> | [Logarithm: base 2](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198820) | **Create field** - Returns the base-2 logarithm of the selected number. | `log2(number) → float` |
> | [Logarithm: natural / arbitrary base](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198908) | **Create field** - Returns the base-e logarithm of the selected number. Optionally, you can add a second argument to calculate the log base x of a given number. | `log(number) → float`<br>`log(base_number, number) → float` |
> | [Longitude](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197724) | **Create field** - Returns the longitude of a given geocoord. | `longitude(geocoord) → float` |
> | [Lower case](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201214) | **Create field** - Adds a new field that converts a string to lowercase letters. | `lower(string) → string` |
> 
> > Macro (rw-tab)
> 
> | **Operation name** | **Description** | **Valid formats** |
> | --- | --- | --- |
> | [Make array](https://devodocs.atlassian.net/wiki/spaces/latest/pages/386891796) | **Create field **- Creates an array from the given integer value(s). | `select[integer1, integer2] →  Array` |
> | [Make byte array](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193991) | **Create field** - Creates a byte array from the given integer values (one or more). | `mkboxar(integer1, integer2, integer3...) → boxar(int1)` |
> | [Make map](https://devodocs.atlassian.net/wiki/spaces/latest/pages/388169736) | **Create field - **Creates a map from given keys and values. | `select{key: value} → map` |
> | [Make set](https://devodocs.atlassian.net/wiki/spaces/latest/pages/389152782) | **Create field **- Creates a set from the given value(s).<br>To convert a complex data type to *set *data type, use the [To Set ](https://devodocs.atlassian.net/wiki/spaces/latest/pages/389349389)operation. | `select {Array} → set` |
> | [Make tuple](https://devodocs.atlassian.net/wiki/spaces/latest/pages/617119745) | **Create field **- Creates a tuple from the given integer value(s). | `select(integer1, integer2) →  Array` |
> | [Matches](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201242) | **Filter** - Returns those strings that match an indicated regular expression.<br>**Create field** - Adds a new Boolean field that shows *true *when a string matches an indicated regular expression.<br>Note that when you enter a string value as a regular expression using LINQ, you have to transform it to *regexp* format using the [Regular expression, regexp (re)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194082) operation, as you can see in the examples. This is not needed if you perform this operation directly from the search window interface. | `string ~ re(string) → boolean`<br>`string ~ regexp → boolean`<br>`matches(string, re(string)) → boolean`<br>`matches(string, regexp) → boolean` |
> | [Maximum](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192430) | **Aggregation** - Returns the highest value of the selected field in each group<br>**Create field** - Creates a field that shows the highest value in two or more numeric fields or values.<br>See also [Minimum (min)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192516) | `max(number)`  `→ number  ` This format is only valid if you use the **Aggregation** operation, that is to say, you must group your data before using it.<br>`max(number1, number2, number3...) → number ` |
> | [MD5 hash function](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194897) | **Create field** - Creates an MD5 hash as a byte array of the given string. | `md5(string) → boxar(int1)` |
> | [Median / 2nd quartile / Percentile 50](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192482) | **Aggregation** - Returns the median of the values of the selected field in each group. | `median(integer) → integer` |
> | [Millisecond](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195319) | **Create field** - Returns the duration representation of 1 millisecond, or the milliseconds corresponding to a given timestamp. Optionally, you can add a timezone different than your current one. | `millisecond() → 1 `<br>`millisecond(timestamp) → integer`<br>`millisecond(timestamp, timezone_string) → integer` |
> | [Minimum](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192516) | **Aggregation** - Returns the lowest value of the selected field in each group.<br>**Create field** - Creates a field that shows the lowest value in two or more numeric fields or values.<br>See also [Maximum (max)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192430) | `min(number)` `→ number   `This format is only valid if you use the **Aggregation** operation, that is to say, you must group your data before using it.<br>`min(number1, number2, number3...) → number` |
> | [Minute](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195353) | **Create field** - Returns the duration representation of 1 minute, or the minutes corresponding to a given timestamp. Optionally, you can add a timezone different than your current one. | `minute() → 1m`<br>`minute(timestamp) → integer`<br>`minute(timestamp, timezone_string) → integer` |
> | [Minute of the day](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195397) | **Create field** - Returns the number of minutes elapsed since midnight of the given timestamp. Optionally, you can check it in a time zone different than yours. | `minuteofday(timestamp)`  → `integer`<br>`minuteofday(timestamp, timezone_string)`  → `integer` |
> | [Modulo](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193417) | **Create field** - Adds a new field that returns the remainder of the division of the integer values in a field by another field or value.<br>Note that the divisor must be always a positive integer value, otherwise a *null* value will be returned.<br>The [Division remainder (rem, %)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193343) operation also returns the remainder of a division, but applies a different formula to calculate it. Go to the operation article to learn more. | `mod(integer1, integer2) → integer`<br>`integer1 %% integer2 → integer` |
> | [Month](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195431) | **Create field** - Returns the month from a given timestamp. Optionally, you can add a timezone different than your current one. | `month(timestamp) → integer`<br>`month(timestamp, timezone_string) → integer` |
> | [Month name](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195465) | **Create field** - Returns the name of the month from a given timestamp. Optionally, you can check it in a time zone different than yours and specify the language in which the month name will appear (*en* by default). | `monthname(timestamp)`  →  `string`<br>`monthname(timestamp, locale_string) `→  `string`<br>`monthname(timestamp, locale_string, timezone_string)`  → `string` |
> | [Month number](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195507) | **Create field** - Returns the number of the month in the year from a given timestamp. This count starts from 1, differing from the [Month](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195431) operation, which starts from 0. Optionally, you can check it in a time zone different than yours. | `monthnumber(timestamp)`  → `integer`<br>`monthnumber(timestamp, timezone_string)`  → `integer` |
> | [Multiplication, product](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193454) | **Create field** - Creates a field that returns the product of two or more numbers or the product of an integer number and a duration. | `number1 * number2 * number3... → number`<br>`mul(number1, number2, number3...) → number`<br>`integer * duration → duration`<br>`mul(integer, duration) → duration` |
> | [Non-null average](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192568) | **Aggregation** - Calculates the average of the non-null values of the selected field in each group. | `nnavg(number) → number` |
> | [Non-null standard deviation (biased)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192602) | **Aggregation** - Calculates the biased standard deviation of the non-null values of the selected field in each group. | `nnstddev(number) → number` |
> | [Non-null standard deviation (unbiased)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192640) | **Aggregation** - Calculates the unbiased standard deviation of the non-null values of the selected field in each group. | `nnustddev(number) → number` |
> | [Non-null variance (biased)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192678) | **Aggregation** - Calculates the biased variance of the non-null values of the selected field in each group. | `nnvar(number) → number` |
> | [Non-null variance (unbiased)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192716) | **Aggregation** - Calculates the unbiased variance of the non-null values of the selected field in each group. | `nnuvar(number) → number` |
> | [Not](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198146) | **Filter** - Returns only the rows where the values in a specified Boolean field are *false*.<br>**Create field** - Creates a Boolean field that returns the complement of the values in another Boolean field (the complement of *true* is *false* and vice versa). | `not boolean → boolean` |
> | [Not equal](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199724) | **Filter** - Compares two values of the same type and returns only the events where both values are not the same.<br>**Create field** - Creates a Boolean field that shows *true* when two values are not the same.<br>This operation is case sensitive, so same values in lowercase and uppercase will be considered as not equal. | `value1 /= value2 → value`<br>`ne(value1, value2) → value` |
> | [Null value locator](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195852) | **Create field** - Adds a new field that returns the value specified as the second argument if the first one is *null*. | `nvl(field_to_check, value_when_null) → value`<br>`field_to_check ?: value_when_null` |
> 
> > Macro (rw-tab)
> 
> | **Operation name** | **Description** | **Valid formats** |
> | --- | --- | --- |
> | [Opaque URI](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201821) | **Filter** - Retrieves only opaque URIs from a specified field.<br>**Create field** - Creates a Boolean field that shows *true* if a given URI is opaque. | `opaqueuri(string) → boolean` |
> | [Or](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198176) | **Filter** - Retrieves those events where at least one of the given Boolean field values is *true*.<br>**Create field** - Creates a Boolean field that returns *true* only if and only if one of the given arguments are *true*. | `boolean1 or boolean2 or ... → boolean` |
> | [Parse date](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194024) | **Create field** - Parses a string representing a date using a custom format, optionally specifying time zone and locale different than your current ones. See the operation article to check the format that the values entered must follow. | `parsedate(string_to_be_parsed, format_string) → string`<br>`parsedate(string_to_be_parsed, format_string, time_zone_string) → string`<br>`parsedate(string_to_be_parsed, format_string, time_zone_string, locale_string) → string` |
> | [Parse geocoord format](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197782) | **Create field** - Parses a string representing a geocoord in a strict format (type:), as produced by the [Represent geocoord format (reprgeo)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197844) operation. If the format is not valid, the result of the parsing will be *null*. | `parsegeo(string) → string` |
> | [Peek](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201272) | **Create field** - The new field returns the part of a string that matches a given regular expression. Optionally, you can add a capturing group to get a specific substring in case of several matches (being the capturing group *0* the first occurrence )<br>Note that when you enter a string value as a regular expression using LINQ, you have to transform it to *regexp* format using the [Regular expression, regexp (re)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194082) operation, as you can see in the examples. This is not needed if you perform this operation directly from the search window interface. | `peek(string, re(string)) → string`<br>`peek(string, regexp) → string`<br>`peek(string, re(string), capturing_group_integer) → string`<br>`peek(string, regexp, capturing_group_integer) → string` |
> | [Percentile 10](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192752) | **Aggregation** - Returns the maximum value of the 10th percentile of the values in the selected group for each group, using linear interpolation. | `percentile10(integer) → integer` |
> | [Percentile 25 / 1st quartile](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192786) | **Aggregation** - Returns the maximum value of the 25th percentile of the values in the selected group for each group, using linear interpolation. | `percentile25(integer) → integer` |
> | [Percentile 5](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192820) | **Aggregation** - Returns the maximum value of the 5th percentile of the values in the selected group for each group, using linear interpolation. | `percentile5(integer) → integer` |
> | [Percentile 75 / 3rd quartile](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192854) | **Aggregation** - Returns the maximum value of the 75th percentile of the values in the selected group for each group, using linear interpolation. | `percentile75(integer) → integer` |
> | [Percentile 90](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192888) | **Aggregation** - Returns the maximum value of the 90th percentile of the values in the selected group for each group, using linear interpolation. | `percentile90(integer) → integer` |
> | [Percentile 95](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192922) | **Aggregation** - Returns the maximum value of the 95th percentile of the values in the selected group for each group, using linear interpolation. | `percentile95(integer) → integer` |
> | [Period](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195543) | **Create field** - Aligns a given timestamp to a specific duration or milliseconds value, considering the UTC value of the timestamp. | `period(timestamp, duration) → timestamp`<br>`period(timestamp, integer) → timestamp` |
> | [Pi (mathematical constant)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198952) | **Create field** - Adds a new field that returns the number Pi (3.141592653589793). | `pi()` |
> | [Power](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193487) | **Create field** - Creates a field that returns the base specified raised to the power of an exponent. | `pow(number_base, number_exponent) → number` |
> | [Pragma value](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199057) | **Create field** -Extracts the pragma value from a given query. | `pragmavalue(language_string, query_string, pragma_key_string) → string` |
> 
> > Macro (rw-tab)
> 
> | **Operation name** | **Description** | **Valid formats** |
> | --- | --- | --- |
> | [Real division](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193553) | **Create field** - Creates a field that returns the real division of two numbers. | `rdiv(number1, number2) → number`<br>`number1 / number2 → number` |
> | [Regular expression, regexp](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194082) | **Create field** - Builds a regular expression from the given string pattern. | `re(string) → regexp` |
> | [Replace all](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201306) | **Create field** - Searches for a value in a given string and returns a new string where all the occurrences (if any) are replaced by another indicated value. | `replaceall(string, string_to_search, string_to_replace) → string` |
> | [Replace first](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201334) | **Create field** - Searches for a value in a given string and returns a new string where only the first occurrence (if any) is replaced by another indicated value. | `replace(string, string_to_search, string_to_replace) → string` |
> | [Represent geocoord format](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197844) | **Create field** - Strict string representation of the given geocoord, in a specific format (type:), where type is the geocoord type. | `reprgeo(geocoord) → geocoord`<br>`reprgeo(geocoord(string)) → geocoord` |
> | [Reverse](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201362) | **Create field **- Reverses the contents of a *string* or *boxarint*. | `reverse(string) → string`<br>`reverse(boxar(int1)) → string` |
> | [Round coordinates](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95197917) | **Create field** - Rounds geo-coordinates according to a grid divided depending on the given latitude and longitude precision (in degrees), or to a uniform grid with a specified number of divisions. | `gridlatlon(geocoord, latitude_float, longitude_float) → geocoord`<br>`gridlatlon(geocoord, grid_size_integer) → geocoord` |
> | [Rounding](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193586) | **Create field** - Adds a new field that rounds the given number to the nearest integer or, if indicated, to a specified number of decimal places.<br>Use [Floor (floor)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193382) if you want to get the largest previous integers, and [Ceiling (ceil)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193240) to round to the smallest following integers. | `round(number) → number`<br>`round(number, integer_decimals) → number` |
> 
> > Macro (rw-tab)
> 
> | **Operation name** | **Description** | **Valid formats** |
> | --- | --- | --- |
> | [Second](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195576) | **Create field** - Returns the duration representation of 1 second, or the seconds from a given timestamp. Optionally, you can add a timezone different than your current one. | `second() → 1s`<br>`second(timestamp) → integer`<br>`second(timestamp, timezone_string) → integer` |
> | [Second of the day](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195610) | **Create field** - Returns the number of seconds elapsed since midnight of the given timestamp. Optionally, you can check it in a time zone different than yours. | `secondofday(timestamp)`  → `integer`<br>`secondofday(timestamp, timezone_string)`  → `integer` |
> | [SHA1 hash function](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194932) | **Create field** - Adds a new field that returns the SHA1 hash as a byte array of the given string. | `sha1(string) → boxar(int1)` |
> | [SHA256 hash function](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194965) | **Create field** - Adds a new field that returns the SHA256 hash as a byte array of the given string. | `sha256(string) → boxar(int1)` |
> | [SHA512 hash function](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194998) | **Create field** - Adds a new field that returns the SHA512 hash as a byte array of the given string. | `sha512(string) → boxar(int1)` |
> | [Shannon entropy](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201407) | **Create field** - The new field returns the Shannon entropy of a given string. | `shannonentropy(string) → float` |
> | [Sign](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193520) | **Create field** - The new field represents the sign of the specified numbers, represented as *1* (positive) or *-1* (negative). Zero values will return *0*. | `signum(number) → integer` |
> | [Sine](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198980) | **Create field** - Adds a new field that calculates the sine of the selected number. | `sin(number) → float` |
> | [Size distinct](https://devodocs.atlassian.net/wiki/spaces/latest/pages/445448454) | **Create field - **Creates a new field counting the size of different values in a given group. | `select sizedistinct(integer) → integer ` |
> | [Sort](https://devodocs.atlassian.net/wiki/spaces/latest/pages/389120003) | **Create field - **Creates a new field sorting the elements of an array in ascending order. You can add a second argument to sort in descending order. | `sort(Array) → array` |
> | [Split](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201437) | **Create field** - Splits a string by a given literal separator and returns only the selected piece (counting from *0*). | `split(string, separator_string, piece_integer) → string` |
> | [Split regexp](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201465) | **Create field** - Splits a string by a given regular expression and returns only the selected piece (counting from *0*).<br>Note that when you enter a string value as a regular expression using LINQ, you have to transform it to *regexp* format using the [Regular expression, regexp (re)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194082) operation, as you can see in the examples. This is not needed if you perform this operation directly from the search window interface. | `splitre(string, re(string), piece_integer) → string`<br>`splitre(string, regexp, piece_integer) → string` |
> | [Square root](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193623) | **Create field** - The new field returns the square root of the values in a numeric field. | `sqrt(number) → float` |
> | [Squid Black Lists Flags](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199505) | **Create field** - Labels a domain according to [Squid Black Lists](http://www.squidguard.org/blacklists.html). If the domain is not included in the blacklist, the field will show no data. | `sbl(domain_string) → string` |
> | [Standard deviation (biased)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192956) | **Aggregation** - Calculates the biased standard deviation of the values in the groups of the selected field. | `stddev(number) → number` |
> | [Standard deviation (unbiased)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95192994) | **Aggregation** - Calculates the unbiased standard deviation of the values in the groups of the selected field. | `ustddev(number) → number` |
> | [Starts with](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201493) | **Filter** - Filters string values that start with a specified prefix.<br>**Create field** - Creates a Boolean field that shows *true *for those strings that start with a specified suffix. | `startswith(string1, string2_prefix) → boolean` |
> | [Substitute](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201526) | **Create field** - Replace the first match of a regular expression in a given string and replaces it by an indicated pattern in *template *format. If no occurrence is found, it returns the original expression or an optional specified value.<br>Note that when you enter a string value as a regular expression and template using LINQ, you have to transform them to *regexp* and *template* format using the [Regular expression, regexp (re)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194082) and [Template (template)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194133) operations, as you can see in the examples. This is not needed if you perform this operation directly from the search window interface. | `subs(string, re(string), template(string)) → string`<br>`subs(string, re(string), template(string), fail_value_string) → string`<br>`subs(string, regexp, template) → string`<br>`subs(string, regexp, template, fail_value_string) → string` |
> | [Substitute all](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201582) | **Create field** - Replace all the matches of a regular expression in a given string and replaces them by an indicated pattern in *template *format. If no occurrence is found, it returns the original expression or an optional specified failed value.<br>Note that when you enter a string value as a regular expression and template using LINQ, you have to transform them to *regexp* and *template* format using the [Regular expression, regexp (re)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194082) and [Template (template)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194133) operations, as you can see in the examples. This is not needed if you perform this operation directly from the search window interface. | `subsall(string, re(string), template(string)) → string`<br>`subsall(string, re(string), template(string), fail_value_string) → string`<br>`subsall(string, regexp, template) → string`<br>`subsall(string, regexp, template, fail_value_string) → string` |
> | [Substring](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201628) | **Create field** - Extracts a substring from a given string, indicating a starting character. Optionally, you can indicate the length of the substrings. If the length is not specified, you will get all the characters from the starting point indicated. | `substring(string, starting_position_integer) → string`<br>`substring(string, starting_position_integer, length_integer) → string` |
> | [Subtraction, minus / Additive inverse](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193656) | **Create field** - Adds a new field that returns the subtraction of two fields or the additive inverse (opposite number) of the values in a given field.<br>Depending on the input data types, this operation retrieves different results. See the [operation article](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193656) for more details. | - number → number
> - duration → duration<br>`number1 - number2 → number`<br>`duration1 - duration2 → duration`<br>`timestamp1 - timestamp2 → duration`<br>`timestamp - duration → timestamp`<br>`sub(number) → number`<br>`sub(duration) → duration`<br>`sub(number1, number2) → number`<br>`sub(duration1, duration2) → duration`<br>`sub(timestamp1, timestamp2) → duration`<br>`sub(timestamp, duration) → timestamp` |
> | [Sum](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193032) | **Aggregation** - Returns the total sum of the values of the selected numeric field in each group. | `sum(number) → number` |
> | [Sum Square](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193064) | **Aggregation** - Returns the total sum of squares of the values of the selected numeric field in each group. | `sum2(number) → number` |
> | [Table name](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199090) | **Create field** - Creates a new field that extracts the table name from a specified query, given its language. | `tablename(language_string, query_string) → string` |
> | [Tangent](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95199015) | **Create field** - Adds a new field that calculates the tangent of a selected number. | `tan(number) → float` |
> | [TCP ACK](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200159) | **Create field** - Returns the acknowledgment number (ACK) of a TCP segment. | `tcpack(packet) → integer` |
> | [TCP checksum](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200175) | **Create field** - Returns the checksum value of a TCP segment. | `tcpcs(packet) → integer` |
> | [TCP destination port](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200191) | **Create field** - Returns the destination port of a TCP segment. | `tcpdst(packet) → integer` |
> | [TCP flags](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200207) | **Create field** - Returns the flags or control bits value of a TCP segment. | `tcpflags(packet) → integer` |
> | [TCP header length](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200223) | **Create field** - Returns the header length or data offset of a TCP segment. The minimum length is 5 words (20 bytes) and the maximum is 15 words (60 bytes). | `tcphl(packet) → integer` |
> | [TCP payload](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200241) | **Create field** - Returns the payload or data section of a TCP segment. | `tcppayload(packet) → boxar(int1)` |
> | [TCP sequence number](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200257) | **Create field** - Returns the sequence number of a TCP segment. | `tcpseq(packet) → boxar(int1)` |
> | [TCP source port](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200273) | **Create field** - Returns the source port of a TCP segment. This value identifies the sending port. | `tcpsrc(packet) → integer` |
> | [TCP status](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200289) | **Create field** - Returns the status of a TCP packet. | `tcpstatus(packet) → string` |
> | [TCP urgent pointer](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200307) | **Create field** - Returns the urgent pointer of a TCP segment.<br>If the URG flag is set, this field is an offset from the sequence number indicating the last urgent data byte. | `tcpurg(packet) → integer` |
> | [TCP window size](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200323) | **Create field** - Returns the received window size of a TCP segment. This field specifies the number of bytes that the sender of the segment is currently willing to receive. | `tcpwin(packet) → integer` |
> | [Template](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194133) | **Create field** - Builds a template from the given string definition. A template is a replacement string (in *template* data type) that also admits capturing groups (for example *\1* will use the capturing group 1 as a template).<br>You can use the templates generated using this operation in the [Substitute (subs)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201526) and [Substitute all (subsall)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201582) operations. | `template(string) → template` |
> | [Timestamp](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194177) | **Create field** - Converts an integer or a valid string (epoch) into normal date format in *timestamp* data type. The string valid format should be *Year-Month-Day Hour:Minute:Second.Millisecond*, where all the fields are numbers. Epoch date should be in milliseconds. See also the [epoch](https://docs.devo.com/confluence/ndt/searching-data/working-in-the-search-window/building-a-query/build-a-query-using-linq/create-new-columns-using-linq#CreatenewcolumnsusingLINQ-epoch) function. | `timestamp(number) → timestamp` |
> | [To array](https://devodocs.atlassian.net/wiki/spaces/latest/pages/389185540) | **Create field **- Creates a new with converting a set to an Array. Use the [Make Array (mkarray)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/386891796) operation for all other data types. | `array(set) → array` |
> | [To base16, b16, hex](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194216) | **Create field** - Returns a hexadecimal (base16) string from the given byte array. | `to16(boxar(int1)) → string` |
> | [To base16](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194248) | **Create field** - Converts an integer to its corresponding hexadecimal number (base 16). | `hex(integer) → string` |
> | [To base64, b64, hex](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194276) | **Create field** - Returns a base64 string from the given byte array. | `to64(boxar(int1)) → string` |
> | [To BigInt](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194296) | **Create field** - Converts a valid number string, a float number, an int, a json that contains a valid number, or a MAC address into a big integer number. Note that float numbers are not rounded, so the result will be the integral part.<br>You can also extract an integer value from a json (*json* data type) using the** **[Jq evaluation (jqeval)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198042) operation and convert it into *integer *type. | `bigint(number_string) → integer`<br>`bigint(float) → integer`<br>`bigint(mac) → integer`<br>`bigint(json_integer) → integer` |
> | [To boolean](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194329) | **Create field** - Transforms the JSON objects in a specified *json* field into *boolean* data type. Note that you must first extract a part of the JSON that represents a Boolean value (*true, false*) using the [Jq evaluation (jqeval)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198042) operation. | `bool(json_boolean) → boolean` |
> | [To Float](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194371) | **Create field** - Converts a valid number string or an integer into a float number.<br>You can also extract a float value from a json (*json* data type) using the** **[Jq evaluation (jqeval)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198042) operation and convert it into *float* type. | `float(number_string) → float`<br>`float(integer) → float`<br>`float(json_float) → float` |
> | [To image](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194423) | **Create field** - Converts a Base64 string into an image. The string values specified must always be preceded by the pattern* extension;base64;* where *extension* is the file extension of the image (for example *png*, *jpg*...). For example: *png;base64;4AAQskZg...* | `image(base64_string) → image` |
> | [To Int](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194458) | **Create field** - Converts a valid number string, a float number or a MAC address into an integer number. Note that float numbers are not rounded, so the result will be the integral part.<br>You can also extract an integer value from a json (*json* data type) using the** **[Jq evaluation (jqeval)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198042) operation and convert it into *integer *type. | `int(number_string) → integer`<br>`int(float) → integer`<br>`int(mac) → integer`<br>`int(json_integer) → integer` |
> | [To IPv4](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194512) | **Create field** - Converts an integer or a string representing an IPv4 address into an IPv4 address in *ip* data type. | `ip4(ipv4_string) → ip`<br>`ip4(ipv4_integer) → ip` |
> | [To IPv4 net](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194540) | **Create field** - Converts a string or integer representing an IPv4 network into *net4* data type. | `net4(net4_string) → net4`<br>`net4(net4_integer) → net4` |
> | [To IPv6 (compatible)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194596) | **Create field** - Converts an IPv4 address into an IPv4-compatible IPv6 address. | `compatible(ip) → ip6` |
> | [To IPv6 ](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194568) | **Create field** - Converts a string representing an IPv4 address or an IPv4 address in *ip* data type into an IPv6 address | `ip6(ipv4_string) → ip6`<br>`ip6(ip) → ip6` |
> | [To IPv6 (mapped)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194624) | **Create field** - Converts an IPv4 address into an IPv4-mapped IPv6 address. | `mapped(ip) → ip6` |
> | [To IPv6 (translated)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194680) | **Create field** - Converts an IPv4 address into an IPv4-translated IPv6 address. | `translated(ip) → ip6` |
> | [To IPv6 net](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194652) | **Create field** - Converts a string representing an IPv6 network address into *net6* data type. | `net6(ipv4_string) → net6` |
> | [To json](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198015) | **Create field** - Converts a field of *string* data type to *json* data type. The *json* data type is required as an input argument for the [Jq evaluation (jqeval)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198042) operation. | `jsonparse(string) → json` |
> | [To MAC address](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194708) | **Create field** - Converts a valid string or integer into a MAC address. | `mac(string) → mac`<br>`mac(integer) → mac` |
> | [To set](https://devodocs.atlassian.net/wiki/spaces/latest/pages/389349389) | **Create field **- Creates a new field converting a given array into a set. | `set(array) → Set` |
> | [To string (str)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194741) | **Create field** - Converts an *integer*, *float*, *timestamp*, *ip, geocoord *or *mac *type value into* string *data type.<br>You can also extract a string value from a json (*json* data type) using the** **[Jq evaluation (jqeval)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95198042) operation and convert it into *string *type. | `str(field) → string`<br>`str(json_string) → string` |
> | [To string (stringify)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194793) | **Create field** - Converts a JSON object (*json* data type) into* string *data type. | `stringify(json) → string` |
> | [To UTF8](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194853) | **Create field** - Creates a byte array from a UTF8 string. | `toutf8(utf8_string) → boxar(int1)` |
> | [To Z85, base85](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95194821) | **Create field** - Returns a Z85 string from the given byte array. | `toz85(boxar(int1)) → string` |
> | [Today](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195644) | **Create field** - Returns the start time of the current day, considering your current time zone. Optionally, you can add a timezone different than your current one. | `today() → timestamp`<br>`today(timezone_string) → timestamp` |
> | [Tomorrow](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195678) | **Create field** - Returns the start time of the following day, considering your current time zone. Optionally, you can add a timezone different than your current one. | `tomorrow() → timestamp`<br>`tomorrow(timezone_string) → timestamp` |
> | [Trim both sides](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201656) | **Create field** - Removes the white space from the beginning and the end of a string. | `trim(string) → string` |
> | [Trim the left side](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201696) | **Create field** - Removes all the extra spaces from the beginning of a string. | `ltrim(string) → string` |
> | [Trim the right side](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201726) | **Create field** - Removes the white space from the end of a string. | `rtrim(string) → string` |
> 
> > Macro (rw-tab)
> 
> | **Operation name** | **Description** | **Valid formats** |
> | --- | --- | --- |
> | [UDP checksum](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200343) | **Create field** - Returns the checksum value of an UDP datagram. This value is used for error checking of the header and data. It carries all-zeros if unused. | `udpcs(packet) → integer` |
> | [UDP destination port](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200377) | **Create field** - Returns the destination port of an UDP datagram. This value identifies the receiving port. | `udpdst(packet) → integer` |
> | [UDP length](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200393) | **Create field** - Returns the length of an UDP datagram. This field specifies the length in bytes of the UDP header and UDP data. | `udplen(packet) → integer` |
> | [UDP payload](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200411) | **Create field** - Returns the payload of an UDP datagram. Note that non-encrypted data can be shown using [From UTF8 (fromutf8)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193875). | `udppayload(packet) → boxar(int1)` |
> | [UDP source port](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200361) | **Create field** - Returns the source port of a UDP datagram. This value identifies the receiving port. | `udpsrc(packet) → integer` |
> | [UDP status](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95200427) | **Create field** - Returns the status of a UDP packet. | `udpstatus(packet) → integer` |
> | [Upper case](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201756) | **Create field** - Adds a new field that converts a string to uppercase letters. | `upper(string) → string` |
> | [URI authority](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201849) | **Create field** - Extracts the authority from a URI (the host part plus the port) and returns a string. | `uriauthority(uri_string) → string` |
> | [URI fragment](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201879) | **Create field** - Extracts the URI fragment in a URI, if exists. | `urifragment(uri_string) → string` |
> | [URI host](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201909) | **Create field** - Extracts the URI host from a URI (the host part, except the port). It also checks the URI authority. | `urihost(uri_string) → string` |
> | [URI path](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201939) | **Create field** - Extracts the URI path from a URI (what comes after the host). | `uripath(uri_string) → string ` |
> | [URI port](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201969) | **Create field** - Extracts the port number from a URI. | `uriport(uri_string) → integer` |
> | [URI query](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95201997) | **Create field** - Extracts the query string from an URI. | `uriquery(uri_string) → string` |
> | [URI scheme](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202027) | **Create field** - Parses a URI to extract the scheme. | `urischeme(uri_string) → string` |
> | [URI ssp](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202057) | **Create field** - Extracts the ssp from a URI. | `urissp(uri_string) → string` |
> | [URI user](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202087) | **Create field** - Parses a URI to extract the user. | `uriuser(uri_string) → string` |
> | [URL decode](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202115) | **Create field** - Decodes the given URL replacing each escape sequence with the character it represents.<br>An escape sequence is formed by a *%* followed by the hex value of a character. | `urldecode(url_string) → string` |
> | [User Agent Company](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202143) | **Create field** - Parses the User Agent to extract the creator company. | `uacompany(ua_string) → string` |
> | [User Agent Company URL](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202159) | **Create field** - Parses the User Agent to extract the creator company URL. | `uacompanyurl(ua_string) → string` |
> | [User Agent Device Icon](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202175) | **Create field** - Parses the User Agent to extract the device type icon. | `uadeviceicon(ua_string) → string` |
> | [User Agent Device Information URL](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202191) | **Create field** - Parses the User Agent to extract the device information URL. | `uadeviceinfourl(ua_string) → string` |
> | [User Agent Device Type](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202207) | **Create field** - Parses the User Agent to extract the device type. | `uadevicetype(ua_string) → string` |
> | [User Agent Family](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202223) | **Create field** - Parses the User Agent to extract its family. | `uafamily(ua_string) → string` |
> | [User Agent Icon](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202239) | **Create field** - Parses the User Agent to extract its icon. | `uaicon(ua_string) → string` |
> | [User Agent Information URL](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202255) | **Create field** - Parses the User Agent to extract its information URL. | `uainfourl(ua_string) → string` |
> | [User Agent is Robot](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202271) | **Filter** - Parses the user agents in a given field and returns only the ones identified as bots.<br>**Create field** - Creates a Boolean field that shows *true* if a user agent string is identified as a robot. | `uaisrobot(ua_string) → boolean` |
> | [User Agent Name](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202287) | **Create field** - Parses the User Agent to extract its name. | `uaname(ua_string) → string` |
> | [User Agent OS Company](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202303) | **Create field** - Parses the User Agent to extract the OS creator company. | `uaoscompany(ua_string) → string` |
> | [User Agent OS Company URL](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202159) | **Create field** - Parses the User Agent to extract the OS creator company URL. | `uaoscompanyurl(ua_string) → string` |
> | [User Agent OS Family](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202335) | **Create field** - Parses the User Agent to extract its OS family. | `uaosfamily(ua_string) → string` |
> | [User Agent OS Icon](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202351) | **Create field** - Parses the User Agent to extract the OS icon. | `uaosicon(ua_string) → string` |
> | [User Agent OS Name](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202367) | **Create field** - Parses the User Agent to extract the OS name. | `uaosname(ua_string) → string` |
> | [User Agent OS URL](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202383) | **Create field** - Parses the User Agent to extract the OS URL. | `uaosurl(ua_string) → string` |
> | [User Agent type](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202399) | **Create field** - Parses the User Agent to extract its type. | `uatype(ua_string) → string` |
> | [User Agent URL](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202415) | **Create field** - Parses the User Agent to extract its URL. | `uaurl(ua_string) → string` |
> | [User Agent Version](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95202431) | **Create field** - Parses the User Agent to extract its version. | `uaversion(ua_string) → string` |
> | [Values](https://devodocs.atlassian.net/wiki/spaces/latest/pages/389251087) | **Create field **- Creates a new field returning the array of values of a given map. | `values(map) → Values` |
> | [Variance (biased)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193096) | **Aggregation** - Calculates the biased variance of the values of the selected field in each group. | `var(number) → float` |
> | [Variance (unbiased)](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95193134) | **Aggregation** - Calculates the unbiased variance of the values of the selected field in each group. | `uvar(number) → float` |
> 
> > Macro (rw-tab)
> 
> 
> > Macro (rw-tab)
> 
> | **Operation name** | **Description** | **Valid formats** |
> | --- | --- | --- |
> | [Year](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195712) | **Create field** - Returns the year from a given timestamp. Optionally, you can add a timezone different than your current one. | `year(timestamp) → integer`<br>`year(timestamp, timezone_string) → integer` |
> | [Yesterday](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95195746) | **Create field** - Returns the start time of the previous day, considering your current time zone. Optionally, you can add a timezone different than your current one. | `yesterday() → timestamp`<br>`year(timezone_string) → timestamp` |