Prometheus按标签子串分组求和查询问题求助
Sum and Group Prometheus Metrics by Substring of the 'index' Label
Got it, let's solve this. Your ElasticSearch index size metric has an index tag formatted like project.<projectname>.<uniqueid>.<date>, and you need to sum the sizes grouped by the <projectname> part. Here's how to do it with Prometheus query functions:
Step-by-Step Query
The core tool here is Prometheus's label_replace function, which lets you extract a substring from an existing label and create a new label for aggregation. Here's the full query (replace elasticsearch_index_size_bytes with your actual metric name):
sum by (project) ( label_replace( elasticsearch_index_size_bytes, "project", "$1", "index", "project\\.(.*?)\\..*" ) )
How This Works
Let's break down each component to make it clear:
label_replaceFunction:- We start with your index size metric, then define a new label called
project. - The regex
project\\.(.*?)\\..*targets theindexlabel format:project\\.matches the literal "project." prefix.(.*?)is a non-greedy capture group that grabs everything between the first and second dot (this is your desired<projectname>).\\..*matches the rest of the string after the second dot (the unique ID and date parts we don't need for grouping).
$1inserts the value captured by the first group into the newprojectlabel.
- We start with your index size metric, then define a new label called
sum by (project):- Once we have the new
projectlabel, we aggregate all metrics by this label, summing up the total index size for each project.
- Once we have the new
Edge Cases to Keep in Mind
- If some indices don't follow the
project.<projectname>.<uniqueid>.<date>format, they won't get theprojectlabel and will be excluded from the sum. If you want to include these (e.g., group them under a "misc" category), you can adjust the regex to be more lenient, but this is usually unnecessary if your naming is consistent. - Double-check your metric name to ensure it matches what's actually being scraped by Prometheus.
Content of the question originates from Stack Exchange, asked by Lars Milland
相关产品推荐
相关产品推荐

