Repository navigation
[timelion] allow sum, subtract, multiply, divide functions to accept seriesList with multiple series - #14891
Conversation
There was a problem hiding this comment.
This is a great improvement, makes a lot of sense intuitively, 👍
The behavior, when the labels in the split-series are not equal, seems a little undefined for a couple of use-cases.
Consider two scenarios (all use logstash example data):
- labels are identical but from different series
consider these two split-series , which are identical:
We cannot substract them:
Fails with:
Error: series could not be found for label q:* > geo.dest:CN > sum(bytes)
at /home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:34:17
at next (native)
at step (/home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:13:191)
at /home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:13:437
at /home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:13:99
at seriesList.list.forEach (/home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:32:7)
at Array.forEach (native)
at /home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:32:23
at next (native)
at step (/home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:13:191)
at /home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:13:361
- labels are not identical
these two series are different:
but subtracting them (which you probably don't want) doesn't yield any useful info
Fails with:
server log [21:29:26.869] [warning][process] Error: series could not be found for label q:* > machine.os.raw:win 7 > sum(bytes)
at /home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:34:17
at next (native)
at step (/home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:13:191)
at /home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:13:437
at /home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:13:99
at seriesList.list.forEach (/home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:32:7)
at Array.forEach (native)
at /home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:32:23
at next (native)
at step (/home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:13:191)
at /home/thomas/repos/kibana/src/core_plugins/timelion/server/lib/reduce.js:13:361
Maybe we should only apply this:
- when the length is equal
- and the labels are equal (not the full series-name, but only the label)
- and the label order is identical
If those cases are not met, we should surface the error. What do you think?
|
Why the third case (label order is identical)? |
1fdd20d to
c21fed0
Compare
|
@thomasneirynck Looks like comparing the labels is a bad idea. The labels contain the metric name and query string so they don't match if you are looking at different metrics or different queries. The |
ff7f068 to
5bef751
Compare
|
@thomasneirynck @ppisljar This PR is ready for another look. |
ppisljar
left a comment
There was a problem hiding this comment.
LGTM, i think it gives nice capabilities, and when you type something that wouldn't work you get the notification warning.
by the way, thomas in the examples above: why would you be doing the split on two different fields, whats the use case?
|
@ppisljar I think it might be useful to run a calculation on two different series when the concept in the two fields are the same. say e.g. to a delta comparison between sum of two fields, split over a couple of terms. Those terms may be the same concept, e.g. zipcode, country-code, username, ... |
|
@thomasneirynck i agree, but i guess you should always split on a same field ... so first serie would be sum of bytes (split on top 5 countries) and second series might be the count (again on the same split). Dont see the usecase where you would want to first split on geo.src and in then on geo.dest ... it won't give you same top5 countries, so it won't make any sense to divide bytes from US by count from china ? |
… and query strings
865641d to
b1888df
Compare
|
@ppisljar makes sense.that example seems not a real-world use-case after all. i thought ordering could also be determined by the terms themselves. |
…seriesList with multiple series (elastic#14891) * allow seriesList with multiple series * remove junk file * fix promise bug in precision.js * remove another junk file * throw error outside of async function so it is properly handled * compare split label and not entire series label which includes metric and query strings * reduce seriesList by label field when both seriesList do not contain splitKey field * use clearer variable names * move pairwiseReduce to its own function * fix es.js test
…seriesList with multiple series (#14891) (#15413) * allow seriesList with multiple series * remove junk file * fix promise bug in precision.js * remove another junk file * throw error outside of async function so it is properly handled * compare split label and not entire series label which includes metric and query strings * reduce seriesList by label field when both seriesList do not contain splitKey field * use clearer variable names * move pairwiseReduce to its own function * fix es.js test
|
What is the first release this PR made it into? I looked everywhere and couldn't find anything like it. |
|
It will be in the next released version - 6.2 |
|
Thanks! 👍 |
…seriesList with multiple series (elastic#14891) * allow seriesList with multiple series * remove junk file * fix promise bug in precision.js * remove another junk file * throw error outside of async function so it is properly handled * compare split label and not entire series label which includes metric and query strings * reduce seriesList by label field when both seriesList do not contain splitKey field * use clearer variable names * move pairwiseReduce to its own function * fix es.js test
fixes #13781
Allow something like:
Another example
.es(index=logstash-*,split=machine.os.raw:5).add(.es(index=logstash-*,split=machine.os.raw:5))SeriesList are applied label-wise to each other resulting in one series per split.