Documentation

CombineNode

The combine node combines data from a single node with itself. Points with the same time are grouped and then combinations are created. The size of the combinations is defined by how many expressions are given. Combinations are order-independent and will never include the same point multiple times.

In the following example, data points for the login service are combined with the data points from all other services:

stream
  |from()
    .measurement('request_latency')
  |combine(lambda: "service" == 'login', lambda: TRUE)
    .as('login', 'other')
    // points that are within 1 second are considered the same time.
    .tolerance(1s)
    // delimiter for new field and tag names
    .delimiter('.')
  // Change group by to be new other.service tag
  |groupBy('other.service')
  // Both the "value" fields from each data point have been prefixed
  // with the respective names 'login' and 'other'.
  |eval(lambda: "login.value" / "other.value")
    .as('ratio')
  ...

In the following example, all combination pairs are created:

|combine(lambda: TRUE, lambda: TRUE)
  .as('login', 'other')

In the following example, all combinations triples are created:

|combine(lambda: TRUE, lambda: TRUE, lambda: TRUE)
  .as('login', 'other', 'another')

Constructor

Chaining MethodDescription
combine ( expressions ...ast.LambdaNode)Combine this node with itself. The data is combined on timestamp.

Property Methods

SettersDescription
as ( names ...string)Prefix names for all fields from the respective nodes. Each field from the parent nodes will be prefixed with the provided name and a ‘.’. See the example above.
delimiter ( value string)The delimiter between the As names and existing field an tag keys. Can be the empty string, but you are responsible for ensuring conflicts are not possible if you use the empty string.
max ( value int64)Maximum number of possible combinations. Since the number of possible combinations can grow very rapidly you can set a maximum number of combinations allowed. If the max is crossed, an error is logged and the combinations are not calculated. Default: 10,000
quiet ( )Suppress all error logging events from this node.
tolerance ( value time.Duration)The maximum duration of time that two incoming points can be apart and still be considered to be equal in time. The joined data point’s time will be rounded to the nearest multiple of the tolerance duration.

Chaining Methods

Alert, Barrier, Bottom, ChangeDetect, Combine, Count, CumulativeSum, Deadman, Default, Delete, Derivative, Difference, Distinct, Ec2Autoscale, Elapsed, Eval, First, Flatten, GroupBy, HoltWinters, HoltWintersWithFit, HttpOut, HttpPost, InfluxDBOut, Join, K8sAutoscale, KapacitorLoopback, Last, Log, Mean, Median, Min, Mode, MovingAverage, Percentile, Sample, Shift, Sideload, Spread, StateCount, StateDuration, Stats, Stddev, Sum, SwarmAutoscale, Top, Trickle, Union, Where, Window


Properties

Property methods modify state on the calling node. They do not add another node to the pipeline, and always return a reference to the calling node. Property methods are marked using the . operator.

As

Prefix names for all fields from the respective nodes. Each field from the parent nodes will be prefixed with the provided name and a .. See the example above.

The names cannot have a dot . character.

combine.as(names ...string)

Delimiter

The delimiter between the As names and existing field an tag keys. Can be the empty string, but you are responsible for ensuring conflicts are not possible if you use the empty string.

combine.delimiter(value string)

Max

Maximum number of possible combinations. Since the number of possible combinations can grow very rapidly, you can set a maximum number of combinations allowed. If the max is exceeded, an error is logged and the combinations are not calculated.

Default: 10,000

combine.max(value int64)

Quiet

Suppress all error logging events from this node.

combine.quiet()

Tolerance

The maximum duration of time that two incoming points can be apart and still be considered to be equal in time. The joined data point’s time will be rounded to the nearest multiple of the tolerance duration.

combine.tolerance(value time.Duration)

Chaining Methods

Chaining methods create a new node in the pipeline as a child of the calling node. They do not modify the calling node. Chaining methods are marked using the | operator.

Alert

Create an alert node, which can trigger alerts.

combine|alert()

Returns: AlertNode

Barrier

Create a new Barrier node that emits a BarrierMessage periodically.

One BarrierMessage will be emitted every period duration.

combine|barrier()

Returns: BarrierNode

Bottom

Select the bottom num points for field and sort by any extra tags or fields.

combine|bottom(num int64, field string, fieldsAndTags ...string)

Returns: InfluxQLNode

ChangeDetect

Create a new node that only emits new points if different from the previous point.

combine|changeDetect(field string)

Returns: ChangeDetectNode

Combine

Combine this node with itself. The data is combined on timestamp.

combine|combine(expressions ...ast.LambdaNode)

Returns: CombineNode

Count

Count the number of points.

combine|count(field string)

Returns: InfluxQLNode

CumulativeSum

Compute a cumulative sum of each point that is received. A point is emitted for every point collected.

combine|cumulativeSum(field string)

Returns: InfluxQLNode

Deadman

Helper function for creating an alert on low throughput, a.k.a. deadman’s switch.

  • Threshold: trigger alert if throughput drops below threshold in points/interval.
  • Interval: how often to check the throughput.
  • Expressions: optional list of expressions to also evaluate. Useful for time of day alerting.

Example:

    var data = stream
        |from()...
    // Trigger critical alert if the throughput drops below 100 points per 10s and checked every 10s.
    data
        |deadman(100.0, 10s)
    //Do normal processing of data
    data...

The above is equivalent to this example:

    var data = stream
        |from()...
    // Trigger critical alert if the throughput drops below 100 points per 10s and checked every 10s.
    data
        |stats(10s)
            .align()
        |derivative('emitted')
            .unit(10s)
            .nonNegative()
        |alert()
            .id('node \'stream0\' in task \'{{ .TaskName }}\'')
            .message('{{ .ID }} is {{ if eq .Level "OK" }}alive{{ else }}dead{{ end }}: {{ index .Fields "emitted" | printf "%0.3f" }} points/10s.')
            .crit(lambda: "emitted" <= 100.0)
    //Do normal processing of data
    data...

The id and message alert properties can be configured globally via the ‘deadman’ configuration section.

Since the AlertNode is the last piece it can be further modified as usual. Example:

    var data = stream
        |from()...
    // Trigger critical alert if the throughput drops below 100 points per 10s and checked every 10s.
    data
        |deadman(100.0, 10s)
            .slack()
            .channel('#dead_tasks')
    //Do normal processing of data
    data...

You can specify additional lambda expressions to further constrain when the deadman’s switch is triggered. Example:

    var data = stream
        |from()...
    // Trigger critical alert if the throughput drops below 100 points per 10s and checked every 10s.
    // Only trigger the alert if the time of day is between 8am-5pm.
    data
        |deadman(100.0, 10s, lambda: hour("time") >= 8 AND hour("time") <= 17)
    //Do normal processing of data
    data...
combine|deadman(threshold float64, interval time.Duration, expr ...ast.LambdaNode)

Returns: AlertNode

Default

Create a node that can set defaults for missing tags or fields.

combine|default()

Returns: DefaultNode

Delete

Create a node that can delete tags or fields.

combine|delete()

Returns: DeleteNode

Derivative

Create a new node that computes the derivative of adjacent points.

combine|derivative(field string)

Returns: DerivativeNode

Difference

Compute the difference between points independent of elapsed time.

combine|difference(field string)

Returns: InfluxQLNode

Distinct

Produce batch of only the distinct points.

combine|distinct(field string)

Returns: InfluxQLNode

Ec2Autoscale

Create a node that can trigger autoscale events for a ec2 autoscalegroup.

combine|ec2Autoscale()

Returns: Ec2AutoscaleNode

Elapsed

Compute the elapsed time between points.

combine|elapsed(field string, unit time.Duration)

Returns: InfluxQLNode

Eval

Create an eval node that will evaluate the given transformation function to each data point. A list of expressions may be provided and will be evaluated in the order they are given. The results are available to later expressions.

combine|eval(expressions ...ast.LambdaNode)

Returns: EvalNode

First

Select the first point.

combine|first(field string)

Returns: InfluxQLNode

Flatten

Flatten points with similar times into a single point.

combine|flatten()

Returns: FlattenNode

GroupBy

Group the data by a set of tags.

Can pass literal * to group by all dimensions. Example:

    |groupBy(*)
combine|groupBy(tag ...interface{})

Returns: GroupByNode

HoltWinters

Compute the Holt-Winters (/influxdb/v1/query_language/functions/#holt-winters) forecast of a data set.

combine|holtWinters(field string, h int64, m int64, interval time.Duration)

Returns: InfluxQLNode

HoltWintersWithFit

Compute the Holt-Winters (/influxdb/v1/query_language/functions/#holt-winters) forecast of a data set. This method also outputs all the points used to fit the data in addition to the forecasted data.

combine|holtWintersWithFit(field string, h int64, m int64, interval time.Duration)

Returns: InfluxQLNode

HttpOut

Create an HTTP output node that caches the most recent data it has received. The cached data is available at the given endpoint. The endpoint is the relative path from the API endpoint of the running task. For example, if the task endpoint is at /kapacitor/v1/tasks/<task_id> and endpoint is top10, then the data can be requested from /kapacitor/v1/tasks/<task_id>/top10.

combine|httpOut(endpoint string)

Returns: HTTPOutNode

HttpPost

Creates an HTTP Post node that POSTS received data to the provided HTTP endpoint. HttpPost expects 0 or 1 arguments. If 0 arguments are provided, you must specify an endpoint property method.

combine|httpPost(url ...string)

Returns: HTTPPostNode

InfluxDBOut

Create an influxdb output node that will store the incoming data into InfluxDB.

combine|influxDBOut()

Returns: InfluxDBOutNode

Join

Join this node with other nodes. The data is joined on timestamp.

combine|join(others ...Node)

Returns: JoinNode

K8sAutoscale

Create a node that can trigger autoscale events for a Kubernetes cluster.

combine|k8sAutoscale()

Returns: K8sAutoscaleNode

KapacitorLoopback

Create an kapacitor loopback node that will send data back into Kapacitor as a stream.

combine|kapacitorLoopback()

Returns: KapacitorLoopbackNode

Last

Select the last point.

combine|last(field string)

Returns: InfluxQLNode

Log

Create a node that logs all data it receives.

combine|log()

Returns: LogNode

Mean

Compute the mean of the data.

combine|mean(field string)

Returns: InfluxQLNode

Median

Compute the median of the data.

Note: This method is not a selector. If you want the median point, use .percentile(field, 50.0).

combine|median(field string)

Returns: InfluxQLNode

Min

Select the minimum point.

combine|min(field string)

Returns: InfluxQLNode

Mode

Compute the mode of the data.

combine|mode(field string)

Returns: InfluxQLNode

MovingAverage

Compute a moving average of the last window points. No points are emitted until the window is full.

combine|movingAverage(field string, window int64)

Returns: InfluxQLNode

Percentile

Select a point at the given percentile. This is a selector function, no interpolation between points is performed.

combine|percentile(field string, percentile float64)

Returns: InfluxQLNode

Sample

Create a new node that samples the incoming points or batches.

One point will be emitted every count or duration specified.

combine|sample(rate interface{})

Returns: SampleNode

Shift

Create a new node that shifts the incoming points or batches in time.

combine|shift(shift time.Duration)

Returns: ShiftNode

Sideload

Create a node that can load data from external sources.

combine|sideload()

Returns: SideloadNode

Spread

Compute the difference between min and max points.

combine|spread(field string)

Returns: InfluxQLNode

StateCount

Create a node that tracks number of consecutive points in a given state.

combine|stateCount(expression ast.LambdaNode)

Returns: StateCountNode

StateDuration

Create a node that tracks duration in a given state.

combine|stateDuration(expression ast.LambdaNode)

Returns: StateDurationNode

Stats

Create a new stream of data that contains the internal statistics of the node. The interval represents how often to emit the statistics based on real time. This means the interval time is independent of the times of the data points the source node is receiving.

combine|stats(interval time.Duration)

Returns: StatsNode

Stddev

Compute the standard deviation.

combine|stddev(field string)

Returns: InfluxQLNode

Sum

Compute the sum of all values.

combine|sum(field string)

Returns: InfluxQLNode

SwarmAutoscale

Create a node that can trigger autoscale events for a Docker swarm cluster.

combine|swarmAutoscale()

Returns: SwarmAutoscaleNode

Top

Select the top num points for field and sort by any extra tags or fields.

combine|top(num int64, field string, fieldsAndTags ...string)

Returns: InfluxQLNode

Trickle

Create a new node that converts batch data to stream data.

combine|trickle()

Returns: TrickleNode

Union

Perform the union of this node and all other given nodes.

combine|union(node ...Node)

Returns: UnionNode

Where

Create a new node that filters the data stream by a given expression.

combine|where(expression ast.LambdaNode)

Returns: WhereNode

Window

Create a new node that windows the stream by time.

NOTE: Window can only be applied to stream edges.

combine|window()

Returns: WindowNode


Was this page helpful?

Thank you for your feedback!


The future of Flux

Flux is going into maintenance mode. You can continue using it as you currently are without any changes to your code.

Read more

InfluxDB 3 Open Source Now in Public Alpha

InfluxDB 3 Open Source is now available for alpha testing, licensed under MIT or Apache 2 licensing.

We are releasing two products as part of the alpha.

InfluxDB 3 Core, is our new open source product. It is a recent-data engine for time series and event data. InfluxDB 3 Enterprise is a commercial version that builds on Core’s foundation, adding historical query capability, read replicas, high availability, scalability, and fine-grained security.

For more information on how to get started, check out: