Subqueries
PromQL's subqueries and pipeline operators enable advanced data processing and nested query logic, essential for complex observability scenarios. Subqueries allow you to embed one query within another, while pipeline operators transform time series data by grouping, joining, or filtering metrics. These features are critical for building dynamic, reusable metrics pipelines in Prometheus.
Subqueries: Nesting Metrics Queries¶
Subqueries let you execute one query as part of another, enabling hierarchical data processing. They are defined using parentheses () and are often used to compute intermediate results that drive subsequent calculations.
Syntax¶
Example: Threshold Detection¶
http_requests_latency_seconds{job="api"} > (avg_over_time(http_requests_latency_seconds{job="api"}[5m]) * 2)
Use Cases¶
- Derived metrics: Compute a baseline metric (e.g., average) and compare against it.
- Aggregation pipelines: Use subquery results as inputs for further filtering or grouping.
Note: Subqueries are evaluated first, and their results are treated as static values in the outer query.
Pipeline Operators: Transforming Time Series Data¶
Pipeline operators reshape time series data by grouping, joining, or filtering metrics. They are applied in sequence using the | symbol and are fundamental for correlating metrics across labels.
Core Operators¶
| Operator | Description |
|---|---|
by |
Groups time series by specified labels. |
without |
Groups time series by all labels except specified ones. |
group_left |
Joins metrics using left outer join based on matching labels. |
group_right |
Joins metrics using right outer join based on matching labels. |
Example: Joining Metrics¶
This query joins request counts with response times using thejob label, preserving all time series from the left side.
Example: Aggregation Pipeline¶
Groups errors by job and status code, then sums them over time.Tip: Pipeline operators are applied in the order they appear, enabling complex data transformations.
Advanced Use Cases¶
Subquery + Pipeline Operators¶
Combine subqueries with pipeline operators for multi-stage processing:
1. Compute average latency per job. 2. Track increases over time. 3. Identify top 5 jobs with rising latency.Dynamic Label Filtering¶
Use by and without to dynamically filter metrics:
Key Takeaways¶
- Subqueries enable nested metrics processing, ideal for deriving thresholds or baselines.
- Pipeline operators reshape time series data via grouping, joining, and filtering.
- Combine subqueries with operators to build multi-stage observability pipelines.
- Use
by/withoutfor label-based aggregation andgroup_left/group_rightfor metric correlation.