Skip to content

Better default for over_time aggregation #138702

@dnhatn

Description

@dnhatn

Currently, when a time-series aggregation does not specify an inner over_time aggregation, we default to using last_over_time. However, this approach is not suitable for types that require a different default over_time aggregation, such as exponential_histogram. Also, if the internal aggregation is not an original field (e.g., TS .. | STATS sum(a + b)), the correct rewrite should be TS .. | STATS SUM(last_over_time(a) + last_over_time(b)) instead.

Relates #138563

Metadata

Metadata

Assignees

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions