Serial differencing 집계
Serial differencing 집계
serial_diff 집계는 현재 버킷과 이전 버킷의 지표 값 사이의 차이를 계산하는 부모 파이프라인(parent pipeline) 집계예요. 결과를 현재 버킷에 저장해요.
출처: 문서
본문
serial_diff 집계는 현재 버킷과 이전 버킷의 지표 값 사이의 차이를 계산하는 부모 파이프라인(parent pipeline) 집계입니다. 결과를 현재 버킷에 저장합니다.
serial_diff 집계를 사용하면 지정된 시차(lag)로 기간 사이의 변화를 계산할 수 있습니다. lag 파라미터(양의 정수 값)는 현재 버킷에서 뺄 이전 버킷 값을 지정합니다. 기본 lag 값은 1로, serial_diff는 현재 버킷의 값에서 바로 이전 버킷의 값을 뺍니다.
파라미터
serial_diff 집계는 다음 파라미터를 받습니다.
| 파라미터 | 필수/선택 | 데이터 타입 | 설명 |
|---|---|---|---|
buckets_path |
필수 | String | 집계할 집계 버킷들의 경로입니다. Buckets path를 참고하세요. |
gap_policy |
선택 | String | 누락된 데이터에 적용할 정책입니다. 유효한 값은 skip과 insert_zeros이며 기본값은 skip입니다. Data gaps를 참고하세요. |
format |
선택 | String | DecimalFormat 서식 문자열입니다. 집계의 value_as_string 속성에 서식이 적용된 출력을 반환합니다. |
lag |
선택 | Integer | 현재 버킷에서 뺄 과거 버킷입니다. 양의 정수여야 합니다. 기본값은 1입니다. |
예제
다음 예제는 OpenSearch Dashboards logs 샘플 데이터에서 한 달 간격의 날짜 히스토그램을 만듭니다. sum 서브 집계가 매달 모든 bytes의 합계를 계산합니다. 마지막으로 serial_diff 집계가 이 합계들에서 총 bytes의 월 대 월 차이를 계산합니다.
GET opensearch_dashboards_sample_data_logs/_search
{
"size": 0,
"aggs": {
"monthly_bytes": {
"date_histogram": {
"field": "@timestamp",
"calendar_interval": "month"
},
"aggs": {
"total_bytes": {
"sum": {
"field": "bytes"
}
},
"monthly_bytes_change": {
"serial_diff": {
"buckets_path": "total_bytes",
"lag": 1
}
}
}
}
}
}
응답에는 두 번째와 세 번째 달의 월 대 월 차이가 포함됩니다. (첫 번째 달은 비교할 이전 달이 없으므로 serial_diff를 계산할 수 없습니다.)
{
"took": 3,
"timed_out": false,
"_shards": {
"total": 1,
"successful": 1,
"skipped": 0,
"failed": 0
},
"hits": {
"total": {
"value": 10000,
"relation": "gte"
},
"max_score": null,
"hits": []
},
"aggregations": {
"monthly_bytes": {
"buckets": [
{
"key_as_string": "2025-03-01T00:00:00.000Z",
"key": 1740787200000,
"doc_count": 480,
"total_bytes": {
"value": 2804103
}
},
{
"key_as_string": "2025-04-01T00:00:00.000Z",
"key": 1743465600000,
"doc_count": 6849,
"total_bytes": {
"value": 39103067
},
"monthly_bytes_change": {
"value": 36298964
}
},
{
"key_as_string": "2025-05-01T00:00:00.000Z",
"key": 1746057600000,
"doc_count": 6745,
"total_bytes": {
"value": 37818519
},
"monthly_bytes_change": {
"value": -1284548
}
}
]
}
}
}
다음 꺾은선형 차트는 serial_diff 집계의 결과를 보여 줍니다. x축은 시간을, y축은 전송된 총 bytes의 전월 대비 변화를 나타냅니다. 선 위의 각 데이터 포인트는 해당 월의 총 bytes와 이전 달의 총 bytes 사이의 차이를 반영합니다. 예를 들어 값이 5,000,000이면 시스템이 전월보다 5백만 바이트를 더 전송했음을 의미하고, 음수 값은 감소를 나타냅니다. 첫 번째 달은 비교할 이전 버킷이 없으므로(차이가 정의되지 않음) 선에서 제외됩니다. 선은 두 번째 달부터 시작해 사용 가능한 모든 데이터에 걸쳐 이어집니다.
이 시각화는 시간에 따른 데이터 볼륨의 급증, 급락, 추세를 빠르게 파악하는 데 도움이 됩니다.
예제: 다기간 차이
더 큰 lag 값을 사용하여 각 버킷을 더 과거에 발생한 버킷과 비교할 수 있습니다. 다음 예제는 lag 4로 주간 bytes 데이터의 차이를 계산합니다(즉, 각 버킷이 4주 전 버킷과 비교됨). 이렇게 하면 4주 주기의 변동이 제거됩니다.
GET opensearch_dashboards_sample_data_logs/_search
{
"size": 0,
"aggs": {
"monthly_bytes": {
"date_histogram": {
"field": "@timestamp",
"calendar_interval": "week"
},
"aggs": {
"total_bytes": {
"sum": {
"field": "bytes"
}
},
"monthly_bytes_change": {
"serial_diff": {
"buckets_path": "total_bytes",
"lag": 4
}
}
}
}
}
}
예제 응답
응답에는 주간 버킷 목록이 포함됩니다. serial_diff 집계가 lag 4의 버킷을 사용할 수 있게 되는 다섯 번째 버킷부터 시작된다는 점에 유의하세요.
{
"took": 6,
"timed_out": false,
"_shards": {
"total": 1,
"successful": 1,
"skipped": 0,
"failed": 0
},
"hits": {
"total": {
"value": 10000,
"relation": "gte"
},
"max_score": null,
"hits": []
},
"aggregations": {
"monthly_bytes": {
"buckets": [
{
"key_as_string": "2025-03-24T00:00:00.000Z",
"key": 1742774400000,
"doc_count": 249,
"total_bytes": {
"value": 1531493
}
},
{
"key_as_string": "2025-03-31T00:00:00.000Z",
"key": 1743379200000,
"doc_count": 1617,
"total_bytes": {
"value": 9213161
}
},
{
"key_as_string": "2025-04-07T00:00:00.000Z",
"key": 1743984000000,
"doc_count": 1610,
"total_bytes": {
"value": 9188671
}
},
{
"key_as_string": "2025-04-14T00:00:00.000Z",
"key": 1744588800000,
"doc_count": 1610,
"total_bytes": {
"value": 9244851
}
},
{
"key_as_string": "2025-04-21T00:00:00.000Z",
"key": 1745193600000,
"doc_count": 1609,
"total_bytes": {
"value": 9061045
},
"monthly_bytes_change": {
"value": 7529552
}
},
{
"key_as_string": "2025-04-28T00:00:00.000Z",
"key": 1745798400000,
"doc_count": 1554,
"total_bytes": {
"value": 8713507
},
"monthly_bytes_change": {
"value": -499654
}
},
{
"key_as_string": "2025-05-05T00:00:00.000Z",
"key": 1746403200000,
"doc_count": 1710,
"total_bytes": {
"value": 9544718
},
"monthly_bytes_change": {
"value": 356047
}
},
{
"key_as_string": "2025-05-12T00:00:00.000Z",
"key": 1747008000000,
"doc_count": 1610,
"total_bytes": {
"value": 9155820
},
"monthly_bytes_change": {
"value": -89031
}
},
{
"key_as_string": "2025-05-19T00:00:00.000Z",
"key": 1747612800000,
"doc_count": 1610,
"total_bytes": {
"value": 9025078
},
"monthly_bytes_change": {
"value": -35967
}
},
{
"key_as_string": "2025-05-26T00:00:00.000Z",
"key": 1748217600000,
"doc_count": 895,
"total_bytes": {
"value": 5047345
},
"monthly_bytes_change": {
"value": -3666162
}
}
]
}
}
}