feat(aggregate transform): Add support for event timestamp-based aggregation #24421
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
This PR adds event-time aggregation support to the
aggregatetransform, addressing issues where metrics with different source timestamps but the same processing time are incorrectly aggregated together.I made this PR to address some gaps in #23694. Thank you @adiwab for providing initial implementation.
Problem
Currently, the
aggregatetransform uses system processing time to bucket metrics. This causes issues when:Solution
Introduced a new
time_sourceconfiguration option with two modes:SystemTime(default): Existing behavior, maintains backward compatibilityEventTime: Uses metric timestamps for bucketing, with watermark-based out-of-order event rejectionKey Changes
Configuration Options:
time_source: Choose betweenSystemTime(default) orEventTimeaggregationallowed_lateness_ms: Grace period for accepting late-arriving events (default: 0)use_system_time_for_missing_timestamps: Fallback behavior for events without timestamps (default: false, drops events)max_future_ms: Maximum allowed future timestamp offset to reject clock-skewed events (default: 10000ms)Implementation:
interval_msboundariesevent_time_buckets,event_time_prev_buckets,event_time_multi_buckets) for event-time modeAggregateEventDroppedinternal eventVector configuration
How did you test this PR?
Added 6 new unit tests covering event-time aggregation scenarios:
I've used Sonnet 4.5 to create some scripts that push influxdb metrics to vector with multiple values:
Change Type
Is this a breaking change?
Does this PR include user facing changes?
no-changeloglabel to this PR.References
Notes
@vectordotdev/vectorto reach out to us regarding this PR.pre-pushhook, please see this template.make fmtmake check-clippy(if there are failures it's possible some of them can be fixed withmake clippy-fix)make testgit merge origin masterandgit push.Cargo.lock), pleaserun
make build-licensesto regenerate the license inventory and commit the changes (if any). More details here.