Skip to main content
The extract_all function retrieves all substrings that match a regular expression from a source string. Use this function when you need to capture multiple matches of a pattern, such as extracting all email addresses, URLs, or repeated patterns from log entries.

For users of other query languages

If you come from other query languages, this section explains how to adjust your existing queries to achieve the same results in APL.
In Splunk SPL, you use rex with max_match=0 to extract all matches. APL’s extract_all provides a more direct approach.
In ANSI SQL, extracting all regex matches typically requires recursive queries or database-specific functions. APL’s extract_all simplifies this operation.

Usage

Syntax

Parameters

Returns

Returns a dynamic array containing all matches. For single capture groups, returns a one-dimensional array. For multiple capture groups, returns a two-dimensional array.

Use case examples

Extract all numeric values from URIs to analyze parameter patterns in API requests.Query
Run in PlaygroundOutputThis query extracts all numeric values from URIs, helping analyze how many IDs are typically passed in API requests and their patterns.
  • extract: Extracts only the first match of a regex pattern. Use this when you only need the first occurrence rather than all matches.
  • split: Splits strings by a delimiter into an array. Use this for simpler tokenization without regex complexity.
  • parse_json: Parses JSON strings into dynamic objects. Use this when working with structured JSON data rather than regex patterns.
  • countof_regex: Counts regex pattern occurrences. Use this when you only need the count of matches, not the actual matched text.