You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Timelion条件判断为含error字段的文档添加醒目错误标记?

在Timelion中用条件判断标记错误时间点

当然可以实现!Timelion的函数组合完全能满足你用醒目标识标注错误位置的需求,不用局限于柱状图。我来给你调整方案,让错误点更突出,还能结合主时间序列做条件样式变化。

第一步:替换柱状图为醒目标记点

你当前用.bars()画错误计数的柱状图,换成.points()并调大尺寸,会更直观地标出错误出现的时间点。比如这样:

# 主时间序列(保持你原来的逻辑)
.es(q="_exists_:json.durationGetOwner", index=filebeat-*, metric="avg:json.durationrelinquish", split=json.environment.consensus_type:4)
  .label('$2 $1 duration ms', '^.*duration(\S+) >.*type:(\S+).*$'),
# 错误标记点(替换柱状图为大尺寸红点)
.es(q="json.type:Error AND json.name:monitoring-tests", index=filebeat-*)
  .points(size=12)  # 调大尺寸让标记更醒目
  .color('#ff0000') # 红色高亮
  .label('Error Occurrence')

第二步:给主折线添加条件变色(可选)

如果你想让主时间序列在错误出现的时间点直接变红,能更直观关联错误对指标的影响,可以用.if()函数实现条件判断:

.es(q="_exists_:json.durationGetOwner", index=filebeat-*, metric="avg:json.durationrelinquish", split=json.environment.consensus_type:4)
  .label('$2 $1 duration ms', '^.*duration(\S+) >.*type:(\S+).*$')
  # 当对应时间点有错误时,折线变红;否则用默认蓝色
  .if(
    .es(q="json.type:Error AND json.name:monitoring-tests", index=filebeat-*).count() > 0,
    .color('#ff0000'),
    .color('#2196F3')
  ),
# 叠加错误标记点(双重保险,确保错误位置不被忽略)
.es(q="json.type:Error AND json.name:monitoring-tests", index=filebeat-*)
  .points(size=12)
  .color('#ff0000')
  .shape("triangle") # 换成三角形标记,和折线区分开
  .label('Error Occurrence')

额外优化技巧

  • 调整标记形状:用.shape()可选值有circle(默认)、triangle、square,选和折线差异大的形状更醒目
  • 增加透明度:如果担心标记遮挡主折线,加.opacity(0.8)让标记半透明
  • 调整点的大小:size参数可以根据你的图表尺寸灵活调整,比如10-15之间都很合适

内容的提问来源于stack exchange,提问作者Breedly

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 03:59:46