1- metricsWithoutAggs
1+ timeseriesWithoutAggs
22required_capability: metrics_command
3- METRICS k8s | sort @timestamp DESC, cluster, pod | keep @timestamp,cluster,pod,network.bytes_in,network.cost | limit 5;
3+ TS k8s | sort @timestamp DESC, cluster, pod | keep @timestamp,cluster,pod,network.bytes_in,network.cost | limit 5;
44
55@timestamp:datetime | cluster:keyword | pod: keyword| network.bytes_in:long | network.cost:double
662024-05-10T00:22:59.000Z | qa | one | 206 | 6.25
@@ -10,10 +10,10 @@ METRICS k8s | sort @timestamp DESC, cluster, pod | keep @timestamp,cluster,pod,n
10102024-05-10T00:22:49.000Z | staging | two | 3 | 1.75
1111;
1212
13- metricsWithAggsAndSourceQuoting
13+ timeseriesWithAggsAndSourceQuoting
1414required_capability: metrics_command
1515required_capability: double_quotes_source_enclosing
16- METRICS "k8s" | STATS max_bytes=max(to_long(network.total_bytes_in)) BY cluster | SORT max_bytes DESC;
16+ TS "k8s" | STATS max_bytes=max(to_long(network.total_bytes_in)) BY cluster | SORT max_bytes DESC;
1717
1818max_bytes:long | cluster: keyword
191910797 | qa
@@ -24,47 +24,47 @@ max_bytes:long | cluster: keyword
2424maxRateAndSourceTripleQuoting
2525required_capability: metrics_command
2626required_capability: double_quotes_source_enclosing
27- METRICS k8s | STATS max(rate(network.total_bytes_in, 1minute));
27+ TS k8s | STATS max(rate(network.total_bytes_in, 1minute));
2828
2929max(rate(network.total_bytes_in, 1minute)): double
3030790.4235090751945
3131;
3232
3333maxCost
3434required_capability: metrics_command
35- METRICS k8s | STATS max_cost=max(rate(network.total_cost));
35+ TS k8s | STATS max_cost=max(rate(network.total_cost));
3636
3737max_cost: double
38380.16151685393258428
3939;
4040
4141maxRateAndBytes
4242required_capability: metrics_command
43- METRICS k8s | STATS max(rate(network.total_bytes_in, 1minute)), max(network.bytes_in);
43+ TS k8s | STATS max(rate(network.total_bytes_in, 1minute)), max(network.bytes_in);
4444
4545max(rate(network.total_bytes_in, 1minute)): double | max(network.bytes_in): long
4646790.4235090751945 | 1021
4747;
4848
4949`maxRateAndMarkupBytes`
5050required_capability: metrics_command
51- METRICS k8s | STATS max(rate(network.total_bytes_in, 1minute)), max(network.bytes_in * 1.05);
51+ TS k8s | STATS max(rate(network.total_bytes_in, 1minute)), max(network.bytes_in * 1.05);
5252
5353max(rate(network.total_bytes_in, 1minute)): double | max(network.bytes_in * 1.05): double
5454790.4235090751945 | 1072.05
5555;
5656
5757maxRateAndBytesAndCost
5858required_capability: metrics_command
59- METRICS k8s | STATS max(rate(network.total_bytes_in, 1minute)), max(network.bytes_in), max(rate(network.total_cost));
59+ TS k8s | STATS max(rate(network.total_bytes_in, 1minute)), max(network.bytes_in), max(rate(network.total_cost));
6060
6161max(rate(network.total_bytes_in, 1minute)): double| max(network.bytes_in): long| max(rate(network.total_cost)): double
6262790.4235090751945 | 1021 | 0.16151685393258428
6363;
6464
6565sumRate
6666required_capability: metrics_command
67- METRICS k8s | STATS bytes=sum(rate(network.total_bytes_in)), sum(rate(network.total_cost)) BY cluster | SORT cluster;
67+ TS k8s | STATS bytes=sum(rate(network.total_bytes_in)), sum(rate(network.total_cost)) BY cluster | SORT cluster;
6868
6969bytes: double | sum(rate(network.total_cost)): double | cluster: keyword
707024.49149357711476 | 0.3018995503437827 | prod
@@ -74,7 +74,7 @@ bytes: double | sum(rate(network.total_cost)): double | cluster: keyword
7474
7575oneRateWithBucket
7676required_capability: metrics_command
77- METRICS k8s | STATS max(rate(network.total_bytes_in)) BY time_bucket = bucket(@timestamp,5minute) | SORT time_bucket DESC | LIMIT 2;
77+ TS k8s | STATS max(rate(network.total_bytes_in)) BY time_bucket = bucket(@timestamp,5minute) | SORT time_bucket DESC | LIMIT 2;
7878
7979max(rate(network.total_bytes_in)): double | time_bucket:date
808010.594594594594595 | 2024-05-10T00:20:00.000Z
@@ -83,7 +83,7 @@ max(rate(network.total_bytes_in)): double | time_bucket:date
8383
8484twoRatesWithBucket
8585required_capability: metrics_command
86- METRICS k8s | STATS max(rate(network.total_bytes_in)), sum(rate(network.total_bytes_in)) BY time_bucket = bucket(@timestamp,5minute) | SORT time_bucket DESC | LIMIT 3;
86+ TS k8s | STATS max(rate(network.total_bytes_in)), sum(rate(network.total_bytes_in)) BY time_bucket = bucket(@timestamp,5minute) | SORT time_bucket DESC | LIMIT 3;
8787
8888max(rate(network.total_bytes_in)): double | sum(rate(network.total_bytes_in)): double | time_bucket:date
898910.594594594594595 | 42.70864495221802 | 2024-05-10T00:20:00.000Z
@@ -94,7 +94,7 @@ max(rate(network.total_bytes_in)): double | sum(rate(network.total_bytes_in)): d
9494
9595oneRateWithBucketAndCluster
9696required_capability: metrics_command
97- METRICS k8s | STATS max(rate(network.total_bytes_in)) BY time_bucket = bucket(@timestamp,5minute), cluster | SORT time_bucket DESC, cluster | LIMIT 6;
97+ TS k8s | STATS max(rate(network.total_bytes_in)) BY time_bucket = bucket(@timestamp,5minute), cluster | SORT time_bucket DESC, cluster | LIMIT 6;
9898
9999max(rate(network.total_bytes_in)): double | time_bucket:date | cluster: keyword
10010010.594594594594595 | 2024-05-10T00:20:00.000Z | prod
@@ -107,7 +107,7 @@ max(rate(network.total_bytes_in)): double | time_bucket:date | cluster:
107107
108108BytesAndCostByBucketAndCluster
109109required_capability: metrics_command
110- METRICS k8s | STATS max(rate(network.total_bytes_in)), max(network.cost) BY time_bucket = bucket(@timestamp,5minute), cluster | SORT time_bucket DESC, cluster | LIMIT 6;
110+ TS k8s | STATS max(rate(network.total_bytes_in)), max(network.cost) BY time_bucket = bucket(@timestamp,5minute), cluster | SORT time_bucket DESC, cluster | LIMIT 6;
111111
112112max(rate(network.total_bytes_in)): double | max(network.cost): double | time_bucket:date | cluster: keyword
11311310.594594594594595 | 10.75 | 2024-05-10T00:20:00.000Z | prod
@@ -120,7 +120,7 @@ max(rate(network.total_bytes_in)): double | max(network.cost): double | time_buc
120120
121121oneRateWithBucketAndClusterThenFilter
122122required_capability: metrics_command
123- METRICS k8s | WHERE cluster=="prod" | STATS max(rate(network.total_bytes_in)) BY time_bucket = bucket(@timestamp,5minute), cluster | SORT time_bucket DESC | LIMIT 3;
123+ TS k8s | WHERE cluster=="prod" | STATS max(rate(network.total_bytes_in)) BY time_bucket = bucket(@timestamp,5minute), cluster | SORT time_bucket DESC | LIMIT 3;
124124
125125max(rate(network.total_bytes_in)): double | time_bucket:date | cluster: keyword
12612610.594594594594595 | 2024-05-10T00:20:00.000Z | prod
0 commit comments