Aggregate
Aggregate metrics passing through a topology
Configuration
Example configurations
{
"transforms": {
"my_transform_id": {
"type": "aggregate",
"inputs": [
"my-source-or-transform-id"
]
}
}
}[transforms.my_transform_id]
type = "aggregate"
inputs = ["my-source-or-transform-id"]
transforms:
my_transform_id:
type: aggregate
inputs:
- my-source-or-transform-id
{
"transforms": {
"my_transform_id": {
"type": "aggregate",
"inputs": [
"my-source-or-transform-id"
],
"interval_ms": 10000,
"measure_cpu_usage": false,
"mode": "Auto"
}
}
}[transforms.my_transform_id]
type = "aggregate"
inputs = ["my-source-or-transform-id"]
interval_ms = 10000
measure_cpu_usage = false
mode = "Auto"
transforms:
my_transform_id:
type: aggregate
inputs:
- my-source-or-transform-id
interval_ms: 10000
measure_cpu_usage: false
mode: Auto
event_time
optional objectEvent-time aggregation settings.
When present, metrics are grouped into buckets based on their timestamps rather than when they are processed. Omit this block to keep the default system-time behavior.
event_time.allowed_lateness_ms
optional uintGrace period for late-arriving events, in milliseconds.
Each bucket accepts events until the system clock reaches
bucket_end + allowed_lateness_ms, where bucket_end is the exclusive end of the
event-time window. That cutoff is enforced when events are recorded, not only when a
periodic flush runs. Once a bucket is emitted it is closed permanently; any later
events whose timestamp falls inside it are dropped and counted via
component_discarded_events_total.
Set to 0 for strict ordering (no late events allowed).
event_time.max_future_ms
optional uintMaximum allowed time drift for future events, in milliseconds.
Acts as a clock-skew guard: events whose timestamp is further in the future than this
many milliseconds (relative to the current system time) are dropped and counted via
component_discarded_events_total. Defaults to 10 seconds.
Set to 0 to allow events at any future time.
10000event_time.missing_timestamp
optional string literal enumHow to handle events with missing timestamps.
Metrics that pass through unchanged for the configured mode do not require a timestamp. For metrics that would be bucketed:
drop(default) discards the event and incrementscomponent_discarded_events_totaluse_system_timesynthesizes a timestamp from the current system clock
| Option | Description |
|---|---|
drop | Drop the event and count it via component_discarded_events_total. |
use_system_time | Use the current system time as the event timestamp. |
dropgraph
optional objectExtra graph configuration
Configure output for component when generated with graph command
graph.edge_attributes
optional objectEdge attributes to add to the edges linked to this component’s node in resulting graph
They are added to the edge as provided
graph.edge_attributes.*
required objectgraph.edge_attributes.*.*
required string literalgraph.node_attributes
optional objectNode attributes to add to this component’s node in resulting graph
They are added to the node as provided
graph.node_attributes.*
required string literalinputs
required [string]A list of upstream source or transform IDs.
Wildcards (*) are supported.
See configuration for more info.
interval_ms
optional uintThe interval between flushes, in milliseconds.
Must be greater than zero. During this time frame, metrics (beta) with the same series data (name, namespace, tags, and so on) are aggregated.
10000measure_cpu_usage
optional boolEnable CPU usage metrics for this transform.
When set to true, each poll of the transform task is timed using the OS thread CPU clock
and the accumulated nanoseconds are reported as the component_cpu_usage_ns_total counter,
tagged with component_id, component_kind, and component_type.
Defaults to false. Enable only for transforms where CPU attribution is needed, as it
adds a clock_gettime call on every future poll.
falsemode
optional string literal enumFunction to use for aggregation.
Some of the functions may only function on incremental and some only on absolute metrics.
| Option | Description |
|---|---|
Auto | Default mode. Sums incremental metrics and uses the latest value for absolute metrics. |
Count | Counts metrics for incremental and absolute metrics |
Diff | Returns difference between latest value for absolute; incremental metrics pass through unchanged. |
Latest | Returns the latest value for absolute metrics; incremental metrics pass through unchanged. |
Max | Max value of absolute metric; incremental metrics pass through unchanged. |
Mean | Mean value of absolute metric; incremental metrics pass through unchanged. |
Min | Min value of absolute metric; incremental metrics pass through unchanged. |
Stdev | Stdev value of absolute metric; incremental metrics pass through unchanged. |
Sum | Sums incremental metrics; absolute metrics pass through unchanged. |
AutoInput Types
Outputs
<component_id>
Output Types
Metrics
metric event.Telemetry
Metrics
linkaggregate_events_recorded_total
counteraggregate_failed_updates_total
counterincremental adds, encountered by the aggregate transform.aggregate_flushes_total
countercomponent_discarded_events_total
counterfilter transform, or false if due to an error.component_errors_total
countercomponent_latency_mean_seconds
gaugeThe mean elapsed time, in fractional seconds, that an event spends in a single transform.
This includes both the time spent queued in the transform’s input buffer and the time spent executing the transform itself.
This value is smoothed over time using an exponentially weighted moving average (EWMA).
component_latency_seconds
histogramThe elapsed time, in fractional seconds, that an event spends in a single transform.
This includes both the time spent queued in the transform’s input buffer and the time spent executing the transform itself.
component_received_event_bytes_total
countercomponent_received_events_count
histogramA histogram of the number of events passed in each internal batch in Vector’s internal topology.
Note that this is separate than sink-level batching. It is mostly useful for low level debugging performance issues in Vector due to small internal batches.
component_received_events_total
countercomponent_sent_event_bytes_total
countercomponent_sent_events_total
countertransform_buffer_max_byte_size
gaugeDeprecated
transform_buffer_max_size_bytes.transform_buffer_max_event_size
gaugeDeprecated
transform_buffer_max_size_events.transform_buffer_max_size_bytes
gaugetransform_buffer_max_size_events
gaugetransform_buffer_utilization
histogramtransform_buffer_utilization_level
gaugetransform_buffer_utilization_mean
gaugeutilization
gaugeExamples
Aggregate over 5 seconds
Given this event...[{"metric":{"counter":{"value":1.1},"kind":"incremental","name":"counter.1","tags":{"host":"my.host.com"},"timestamp":"2021-07-12T07:58:44.223543Z"}},{"metric":{"counter":{"value":2.2},"kind":"incremental","name":"counter.1","tags":{"host":"my.host.com"},"timestamp":"2021-07-12T07:58:45.223543Z"}},{"metric":{"counter":{"value":1.1},"kind":"incremental","name":"counter.1","tags":{"host":"different.host.com"},"timestamp":"2021-07-12T07:58:45.223543Z"}},{"metric":{"counter":{"value":22.33},"kind":"absolute","name":"gauge.1","tags":{"host":"my.host.com"},"timestamp":"2021-07-12T07:58:47.223543Z"}},{"metric":{"counter":{"value":44.55},"kind":"absolute","name":"gauge.1","tags":{"host":"my.host.com"},"timestamp":"2021-07-12T07:58:45.223543Z"}}]transforms:
my_transform_id:
type: aggregate
inputs:
- my-source-or-transform-id
interval_ms: 5000
[transforms.my_transform_id]
type = "aggregate"
inputs = ["my-source-or-transform-id"]
interval_ms = 5000
{
"transforms": {
"my_transform_id": {
"type": "aggregate",
"inputs": [
"my-source-or-transform-id"
],
"interval_ms": 5000
}
}
}[{"metric":{"counter":{"value":3.3},"kind":"incremental","name":"counter.1","tags":{"host":"my.host.com"},"timestamp":"2021-07-12T07:58:45.223543Z"}},{"metric":{"counter":{"value":1.1},"kind":"incremental","name":"counter.1","tags":{"host":"different.host.com"},"timestamp":"2021-07-12T07:58:45.223543Z"}},{"metric":{"counter":{"value":44.55},"kind":"absolute","name":"gauge.1","tags":{"host":"my.host.com"},"timestamp":"2021-07-12T07:58:45.223543Z"}}]How it works
Advantages of Use
Aggregation Behavior
incremental metrics
are “added” and newer absolute metrics replace older ones in the same series. This results in a reduction
of volume and less granularity, while maintaining numerical correctness. As an example, two
incremental counter metrics with values 10 and 13 processed by the transform during a period would be
aggregated into a single incremental counter with a value of 23. Two absolute gauge metrics with
values 93 and 95 would result in a single absolute gauge with the value of 95. More complex
types like distribution, histogram, set, and summary behave similarly with incremental
values being combined in a manner that makes sense based on their type.Event-Time Aggregation
When an event_time configuration block is present, metrics are bucketed by the
timestamp on each event rather than by the moment Vector processes it. Bucket
boundaries are aligned to multiples of interval_ms from the Unix epoch, so the
same source timestamp always maps to the same bucket regardless of when Vector
receives it. Omit the event_time block to keep the default system-time behavior.
This is useful when downstream sinks key on the metric timestamp. For example, the Datadog Metrics sink overwrites earlier values for an identical timestamp; bucketing on event time prevents distinct samples from collapsing into a single point.
Watermark and Late Events
Vector tracks a watermark — the exclusive end of the most recently emitted bucket.
Events whose bucket has already been emitted are dropped and counted via
component_discarded_events_total. Use event_time.allowed_lateness_ms to extend
how long each bucket accepts events after its window ends
(bucket_end + allowed_lateness_ms, compared to the system clock). That cutoff
applies when recording an event, not only when the periodic flush runs, so
allowed_lateness_ms = 0 enforces strict lateness even if the flush interval is
long or misaligned.
Metrics the configured mode does not aggregate (for example an incremental
event in mean mode, or an absolute event in sum mode) pass through
unchanged, matching system-time behavior, without creating buckets or affecting
the watermark. Absolute non-gauge values in mean or stdev mode are ignored
(not passed through), also matching system-time behavior.
Missing and Future Timestamps
event_time.missing_timestamp to use_system_time to fall back to the current
system time for bucketed metrics instead. Bucketed events whose timestamp is more
than event_time.max_future_ms ahead of the system clock are dropped as a
clock-skew guard. All such drops increment
component_discarded_events_total (the drop reason is logged, not tagged on
the metric).Shutdown and Reload
diff mode a small rolling window of previous buckets is also
retained to compute deltas across bucket boundaries; other modes do not retain
previous buckets.