Advanced PromQL
Range Vectors for Historical Comparison¶
Range vectors allow you to query data over a time range, enabling comparisons between current and historical metrics. This is critical for detecting anomalies like sudden traffic spikes or gradual performance degradation.
Example: Detecting CPU Usage Anomalies¶
Compare current CPU usage with the same time last week using offset() for alignment:
avg(cpu_utilization{job="app-server"}[5m]) >
avg(cpu_utilization{job="app-server"}[5m])[1w] offset 1w
Example: Trend Analysis with avg_over_time¶
Analyze CPU usage trends over a 7-day window:
Alignment Joins for Synchronized Metrics¶
When comparing metrics from different sources (e.g., HTTP latency vs. database query latency), alignment joins ensure they are evaluated at the same time steps. Use align() to synchronize time series.
Example: Aligning HTTP and Database Metrics¶
This aligns both HTTP and database metrics to 1-minute intervals, enabling direct comparison at the same time steps.Diagram: Alignment Join Workflow¶
[HTTP Latency] [Database Latency]
| |
v v
align() -------------------> [Aligned Metrics]
| |
v v
[Correlation Analysis] [Performance Comparison]
Rate Calculations for Anomaly Detection¶
The rate() function calculates the per-second average rate of increase of a counter, ideal for detecting sudden error spikes or throughput changes.
Example: Detecting Error Rate Anomalies¶
This query flags instances where the error rate exceeds 5% per second, indicating potential service degradation.Example: Combining Rate with Historical Baselines¶
Compares current error rates to historical baselines, alerting on 150% increases.Combining Techniques for Comprehensive Analysis¶
Advanced queries often blend multiple techniques. For example, use align() to synchronize metrics, then apply rate() to detect anomalies in their relationship.
Example: Correlated Anomaly Detection¶
(
rate(
align(
avg(http_request_duration_seconds{job="api"}),
avg(db_query_latency_seconds{job="db"})
)[1m]
)
-
avg_over_time(http_request_duration_seconds{job="api"}[5m])[1w]
) > 0.2
Key takeaways¶
- Range vectors enable historical comparisons, critical for identifying gradual or sudden anomalies.
- Alignment joins synchronize metrics from different sources, ensuring accurate cross-metric analysis.
- Rate calculations reveal per-second changes in counters, ideal for detecting transient issues like error spikes.
- Combine these techniques to build robust anomaly detection pipelines that align with SLOs and error budget management.