You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Prometheus按标签子串分组求和查询问题求助

Sum and Group Prometheus Metrics by Substring of the 'index' Label

Got it, let's solve this. Your ElasticSearch index size metric has an index tag formatted like project.<projectname>.<uniqueid>.<date>, and you need to sum the sizes grouped by the <projectname> part. Here's how to do it with Prometheus query functions:

Step-by-Step Query

The core tool here is Prometheus's label_replace function, which lets you extract a substring from an existing label and create a new label for aggregation. Here's the full query (replace elasticsearch_index_size_bytes with your actual metric name):

sum by (project) (
  label_replace(
    elasticsearch_index_size_bytes,
    "project",
    "$1",
    "index",
    "project\\.(.*?)\\..*"
  )
)

How This Works

Let's break down each component to make it clear:

  • label_replace Function:
    • We start with your index size metric, then define a new label called project.
    • The regex project\\.(.*?)\\..* targets the index label format:
      • project\\. matches the literal "project." prefix.
      • (.*?) is a non-greedy capture group that grabs everything between the first and second dot (this is your desired <projectname>).
      • \\..* matches the rest of the string after the second dot (the unique ID and date parts we don't need for grouping).
    • $1 inserts the value captured by the first group into the new project label.
  • sum by (project):
    • Once we have the new project label, we aggregate all metrics by this label, summing up the total index size for each project.

Edge Cases to Keep in Mind

  • If some indices don't follow the project.<projectname>.<uniqueid>.<date> format, they won't get the project label and will be excluded from the sum. If you want to include these (e.g., group them under a "misc" category), you can adjust the regex to be more lenient, but this is usually unnecessary if your naming is consistent.
  • Double-check your metric name to ensure it matches what's actually being scraped by Prometheus.

Content of the question originates from Stack Exchange, asked by Lars Milland

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:18:40