求助:Splunk mstats统计服务容器数时遇distinct_count不支持错误
解决Splunk统计服务容器数量的查询报错问题
问题原因
你使用的mstats命令不支持distinct_count聚合函数——mstats是专为Splunk metrics索引的数值型指标(如gauge、counter类型的监控值)设计的,仅支持sum、avg、max、min这类针对数值的聚合操作,而统计维度字段的去重数量不在它的支持范围内,因此会抛出Unsupported aggregation type: distinct_count错误。
正确查询语句
既然你仅需统计各服务随时间变化的不同容器ID数量,直接用timechart结合去重统计函数dc()即可,无需使用mstats:
index="my-actuator-index" | timechart dc(container_id) as 运行容器数量 span=auto by service useother=false limit=0 | sort service
语句说明
dc(container_id):统计每个时间窗口内不同容器ID的数量,dc是distinct_count的简写span=auto:让Splunk自动根据查询的时间范围选择合适的时间跨度by service:按服务名称分组统计数据useother=false limit=0:不合并展示未单独列出的服务,完整显示所有服务的统计结果sort service:按服务名称对结果排序
内容的提问来源于stack exchange,提问作者Josh M.
相关产品推荐
相关产品推荐

