blob: 51743c43b3737c052df6afad42d78cc775bc240b [file] [log] [blame]
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta name="description" content="Apache Druid">
<meta name="keywords" content="druid,kafka,database,analytics,streaming,real-time,real time,apache,open source">
<meta name="author" content="Apache Software Foundation">
<title>Druid | Tutorial: Roll-up</title>
<link rel="alternate" type="application/atom+xml" href="/feed">
<link rel="shortcut icon" href="/img/favicon.png">
<link rel="stylesheet" href="https://use.fontawesome.com/releases/v5.7.2/css/all.css" integrity="sha384-fnmOCqbTlWIlj8LyTjo7mOUStjsKC4pOpQbqyi7RrhN7udi9RwhKkMHpvLbHG9Sr" crossorigin="anonymous">
<link href='//fonts.googleapis.com/css?family=Open+Sans+Condensed:300,700,300italic|Open+Sans:300italic,400italic,600italic,400,300,600,700' rel='stylesheet' type='text/css'>
<link rel="stylesheet" href="/css/bootstrap-pure.css?v=1.1">
<link rel="stylesheet" href="/css/base.css?v=1.1">
<link rel="stylesheet" href="/css/header.css?v=1.1">
<link rel="stylesheet" href="/css/footer.css?v=1.1">
<link rel="stylesheet" href="/css/syntax.css?v=1.1">
<link rel="stylesheet" href="/css/docs.css?v=1.1">
<script>
(function() {
var cx = '000162378814775985090:molvbm0vggm';
var gcse = document.createElement('script');
gcse.type = 'text/javascript';
gcse.async = true;
gcse.src = (document.location.protocol == 'https:' ? 'https:' : 'http:') +
'//cse.google.com/cse.js?cx=' + cx;
var s = document.getElementsByTagName('script')[0];
s.parentNode.insertBefore(gcse, s);
})();
</script>
</head>
<body>
<!-- Start page_header include -->
<script src="//ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js"></script>
<div class="top-navigator">
<div class="container">
<div class="left-cont">
<a class="logo" href="/"><span class="druid-logo"></span></a>
</div>
<div class="right-cont">
<ul class="links">
<li class=""><a href="/technology">Technology</a></li>
<li class=""><a href="/use-cases">Use Cases</a></li>
<li class=""><a href="/druid-powered">Powered By</a></li>
<li class=""><a href="/docs/latest/design/">Docs</a></li>
<li class=""><a href="/community/">Community</a></li>
<li class="header-dropdown">
<a>Apache</a>
<div class="header-dropdown-menu">
<a href="https://www.apache.org/" target="_blank">Foundation</a>
<a href="https://www.apache.org/events/current-event" target="_blank">Events</a>
<a href="https://www.apache.org/licenses/" target="_blank">License</a>
<a href="https://www.apache.org/foundation/thanks.html" target="_blank">Thanks</a>
<a href="https://www.apache.org/security/" target="_blank">Security</a>
<a href="https://www.apache.org/foundation/sponsorship.html" target="_blank">Sponsorship</a>
</div>
</li>
<li class=" button-link"><a href="/downloads.html">Download</a></li>
</ul>
</div>
</div>
<div class="action-button menu-icon">
<span class="fa fa-bars"></span> MENU
</div>
<div class="action-button menu-icon-close">
<span class="fa fa-times"></span> MENU
</div>
</div>
<script type="text/javascript">
var $menu = $('.right-cont');
var $menuIcon = $('.menu-icon');
var $menuIconClose = $('.menu-icon-close');
function showMenu() {
$menu.fadeIn(100);
$menuIcon.fadeOut(100);
$menuIconClose.fadeIn(100);
}
$menuIcon.click(showMenu);
function hideMenu() {
$menu.fadeOut(100);
$menuIconClose.fadeOut(100);
$menuIcon.fadeIn(100);
}
$menuIconClose.click(hideMenu);
$(window).resize(function() {
if ($(window).width() >= 840) {
$menu.fadeIn(100);
$menuIcon.fadeOut(100);
$menuIconClose.fadeOut(100);
}
else {
$menu.fadeOut(100);
$menuIcon.fadeIn(100);
$menuIconClose.fadeOut(100);
}
});
</script>
<!-- Stop page_header include -->
<div class="container doc-container">
<p> Looking for the <a href="/docs/0.23.0/">latest stable documentation</a>?</p>
<div class="row">
<div class="col-md-9 doc-content">
<p>
<a class="btn btn-default btn-xs visible-xs-inline-block visible-sm-inline-block" href="#toc">Table of Contents</a>
</p>
<!--
~ Licensed to the Apache Software Foundation (ASF) under one
~ or more contributor license agreements. See the NOTICE file
~ distributed with this work for additional information
~ regarding copyright ownership. The ASF licenses this file
~ to you under the Apache License, Version 2.0 (the
~ "License"); you may not use this file except in compliance
~ with the License. You may obtain a copy of the License at
~
~ http://www.apache.org/licenses/LICENSE-2.0
~
~ Unless required by applicable law or agreed to in writing,
~ software distributed under the License is distributed on an
~ "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
~ KIND, either express or implied. See the License for the
~ specific language governing permissions and limitations
~ under the License.
-->
<h1 id="tutorial-roll-up">Tutorial: Roll-up</h1>
<p>Apache Druid (incubating) can summarize raw data at ingestion time using a process we refer to as &quot;roll-up&quot;. Roll-up is a first-level aggregation operation over a selected set of columns that reduces the size of stored segments.</p>
<p>This tutorial will demonstrate the effects of roll-up on an example dataset.</p>
<p>For this tutorial, we&#39;ll assume you&#39;ve already downloaded Druid as described in
the <a href="index.html">single-machine quickstart</a> and have it running on your local machine.</p>
<p>It will also be helpful to have finished <a href="../tutorials/tutorial-batch.html">Tutorial: Loading a file</a> and <a href="../tutorials/tutorial-query.html">Tutorial: Querying data</a>.</p>
<h2 id="example-data">Example data</h2>
<p>For this tutorial, we&#39;ll use a small sample of network flow event data, representing packet and byte counts for traffic from a source to a destination IP address that occurred within a particular second.</p>
<div class="highlight"><pre><code class="language-json" data-lang="json"><span></span><span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-01T01:01:35Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;1.1.1.1&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;2.2.2.2&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">20</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">9024</span><span class="p">}</span>
<span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-01T01:01:51Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;1.1.1.1&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;2.2.2.2&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">255</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">21133</span><span class="p">}</span>
<span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-01T01:01:59Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;1.1.1.1&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;2.2.2.2&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">11</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">5780</span><span class="p">}</span>
<span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-01T01:02:14Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;1.1.1.1&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;2.2.2.2&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">38</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">6289</span><span class="p">}</span>
<span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-01T01:02:29Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;1.1.1.1&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;2.2.2.2&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">377</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">359971</span><span class="p">}</span>
<span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-01T01:03:29Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;1.1.1.1&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;2.2.2.2&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">49</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">10204</span><span class="p">}</span>
<span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-02T21:33:14Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;7.7.7.7&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;8.8.8.8&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">38</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">6289</span><span class="p">}</span>
<span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-02T21:33:45Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;7.7.7.7&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;8.8.8.8&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">123</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">93999</span><span class="p">}</span>
<span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-02T21:35:45Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;7.7.7.7&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;8.8.8.8&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">12</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">2818</span><span class="p">}</span>
</code></pre></div>
<p>A file containing this sample input data is located at <code>quickstart/tutorial/rollup-data.json</code>.</p>
<p>We&#39;ll ingest this data using the following ingestion task spec, located at <code>quickstart/tutorial/rollup-index.json</code>.</p>
<div class="highlight"><pre><code class="language-json" data-lang="json"><span></span><span class="p">{</span>
<span class="nt">&quot;type&quot;</span> <span class="p">:</span> <span class="s2">&quot;index&quot;</span><span class="p">,</span>
<span class="nt">&quot;spec&quot;</span> <span class="p">:</span> <span class="p">{</span>
<span class="nt">&quot;dataSchema&quot;</span> <span class="p">:</span> <span class="p">{</span>
<span class="nt">&quot;dataSource&quot;</span> <span class="p">:</span> <span class="s2">&quot;rollup-tutorial&quot;</span><span class="p">,</span>
<span class="nt">&quot;parser&quot;</span> <span class="p">:</span> <span class="p">{</span>
<span class="nt">&quot;type&quot;</span> <span class="p">:</span> <span class="s2">&quot;string&quot;</span><span class="p">,</span>
<span class="nt">&quot;parseSpec&quot;</span> <span class="p">:</span> <span class="p">{</span>
<span class="nt">&quot;format&quot;</span> <span class="p">:</span> <span class="s2">&quot;json&quot;</span><span class="p">,</span>
<span class="nt">&quot;dimensionsSpec&quot;</span> <span class="p">:</span> <span class="p">{</span>
<span class="nt">&quot;dimensions&quot;</span> <span class="p">:</span> <span class="p">[</span>
<span class="s2">&quot;srcIP&quot;</span><span class="p">,</span>
<span class="s2">&quot;dstIP&quot;</span>
<span class="p">]</span>
<span class="p">},</span>
<span class="nt">&quot;timestampSpec&quot;</span><span class="p">:</span> <span class="p">{</span>
<span class="nt">&quot;column&quot;</span><span class="p">:</span> <span class="s2">&quot;timestamp&quot;</span><span class="p">,</span>
<span class="nt">&quot;format&quot;</span><span class="p">:</span> <span class="s2">&quot;iso&quot;</span>
<span class="p">}</span>
<span class="p">}</span>
<span class="p">},</span>
<span class="nt">&quot;metricsSpec&quot;</span> <span class="p">:</span> <span class="p">[</span>
<span class="p">{</span> <span class="nt">&quot;type&quot;</span> <span class="p">:</span> <span class="s2">&quot;count&quot;</span><span class="p">,</span> <span class="nt">&quot;name&quot;</span> <span class="p">:</span> <span class="s2">&quot;count&quot;</span> <span class="p">},</span>
<span class="p">{</span> <span class="nt">&quot;type&quot;</span> <span class="p">:</span> <span class="s2">&quot;longSum&quot;</span><span class="p">,</span> <span class="nt">&quot;name&quot;</span> <span class="p">:</span> <span class="s2">&quot;packets&quot;</span><span class="p">,</span> <span class="nt">&quot;fieldName&quot;</span> <span class="p">:</span> <span class="s2">&quot;packets&quot;</span> <span class="p">},</span>
<span class="p">{</span> <span class="nt">&quot;type&quot;</span> <span class="p">:</span> <span class="s2">&quot;longSum&quot;</span><span class="p">,</span> <span class="nt">&quot;name&quot;</span> <span class="p">:</span> <span class="s2">&quot;bytes&quot;</span><span class="p">,</span> <span class="nt">&quot;fieldName&quot;</span> <span class="p">:</span> <span class="s2">&quot;bytes&quot;</span> <span class="p">}</span>
<span class="p">],</span>
<span class="nt">&quot;granularitySpec&quot;</span> <span class="p">:</span> <span class="p">{</span>
<span class="nt">&quot;type&quot;</span> <span class="p">:</span> <span class="s2">&quot;uniform&quot;</span><span class="p">,</span>
<span class="nt">&quot;segmentGranularity&quot;</span> <span class="p">:</span> <span class="s2">&quot;week&quot;</span><span class="p">,</span>
<span class="nt">&quot;queryGranularity&quot;</span> <span class="p">:</span> <span class="s2">&quot;minute&quot;</span><span class="p">,</span>
<span class="nt">&quot;intervals&quot;</span> <span class="p">:</span> <span class="p">[</span><span class="s2">&quot;2018-01-01/2018-01-03&quot;</span><span class="p">],</span>
<span class="nt">&quot;rollup&quot;</span> <span class="p">:</span> <span class="kc">true</span>
<span class="p">}</span>
<span class="p">},</span>
<span class="nt">&quot;ioConfig&quot;</span> <span class="p">:</span> <span class="p">{</span>
<span class="nt">&quot;type&quot;</span> <span class="p">:</span> <span class="s2">&quot;index&quot;</span><span class="p">,</span>
<span class="nt">&quot;firehose&quot;</span> <span class="p">:</span> <span class="p">{</span>
<span class="nt">&quot;type&quot;</span> <span class="p">:</span> <span class="s2">&quot;local&quot;</span><span class="p">,</span>
<span class="nt">&quot;baseDir&quot;</span> <span class="p">:</span> <span class="s2">&quot;quickstart/tutorial&quot;</span><span class="p">,</span>
<span class="nt">&quot;filter&quot;</span> <span class="p">:</span> <span class="s2">&quot;rollup-data.json&quot;</span>
<span class="p">},</span>
<span class="nt">&quot;appendToExisting&quot;</span> <span class="p">:</span> <span class="kc">false</span>
<span class="p">},</span>
<span class="nt">&quot;tuningConfig&quot;</span> <span class="p">:</span> <span class="p">{</span>
<span class="nt">&quot;type&quot;</span> <span class="p">:</span> <span class="s2">&quot;index&quot;</span><span class="p">,</span>
<span class="nt">&quot;maxRowsPerSegment&quot;</span> <span class="p">:</span> <span class="mi">5000000</span><span class="p">,</span>
<span class="nt">&quot;maxRowsInMemory&quot;</span> <span class="p">:</span> <span class="mi">25000</span><span class="p">,</span>
<span class="nt">&quot;forceExtendableShardSpecs&quot;</span> <span class="p">:</span> <span class="kc">true</span>
<span class="p">}</span>
<span class="p">}</span>
<span class="p">}</span>
</code></pre></div>
<p>Roll-up has been enabled by setting <code>&quot;rollup&quot; : true</code> in the <code>granularitySpec</code>.</p>
<p>Note that we have <code>srcIP</code> and <code>dstIP</code> defined as dimensions, a longSum metric is defined for the <code>packets</code> and <code>bytes</code> columns, and the <code>queryGranularity</code> has been defined as <code>minute</code>. </p>
<p>We will see how these definitions are used after we load this data.</p>
<h2 id="load-the-example-data">Load the example data</h2>
<p>From the apache-druid-0.14.2-incubating package root, run the following command:</p>
<div class="highlight"><pre><code class="language-bash" data-lang="bash"><span></span>bin/post-index-task --file quickstart/tutorial/rollup-index.json
</code></pre></div>
<p>After the script completes, we will query the data.</p>
<h2 id="query-the-example-data">Query the example data</h2>
<p>Let&#39;s run <code>bin/dsql</code> and issue a <code>select * from &quot;rollup-tutorial&quot;;</code> query to see what data was ingested.</p>
<div class="highlight"><pre><code class="language-bash" data-lang="bash"><span></span>$ bin/dsql
Welcome to dsql, the command-line client <span class="k">for</span> Druid SQL.
Type <span class="s2">&quot;\h&quot;</span> <span class="k">for</span> help.
dsql&gt; <span class="k">select</span> * from <span class="s2">&quot;rollup-tutorial&quot;</span><span class="p">;</span>
┌──────────────────────────┬────────┬───────┬─────────┬─────────┬─────────┐
│ __time │ bytes │ count │ dstIP │ packets │ srcIP │
├──────────────────────────┼────────┼───────┼─────────┼─────────┼─────────┤
<span class="m">2018</span>-01-01T01:01:00.000Z │ <span class="m">35937</span><span class="m">3</span><span class="m">2</span>.2.2.2 │ <span class="m">286</span><span class="m">1</span>.1.1.1 │
<span class="m">2018</span>-01-01T01:02:00.000Z │ <span class="m">366260</span><span class="m">2</span><span class="m">2</span>.2.2.2 │ <span class="m">415</span><span class="m">1</span>.1.1.1 │
<span class="m">2018</span>-01-01T01:03:00.000Z │ <span class="m">10204</span><span class="m">1</span><span class="m">2</span>.2.2.2 │ <span class="m">49</span><span class="m">1</span>.1.1.1 │
<span class="m">2018</span>-01-02T21:33:00.000Z │ <span class="m">100288</span><span class="m">2</span><span class="m">8</span>.8.8.8 │ <span class="m">161</span><span class="m">7</span>.7.7.7 │
<span class="m">2018</span>-01-02T21:35:00.000Z │ <span class="m">2818</span><span class="m">1</span><span class="m">8</span>.8.8.8 │ <span class="m">12</span><span class="m">7</span>.7.7.7 │
└──────────────────────────┴────────┴───────┴─────────┴─────────┴─────────┘
Retrieved <span class="m">5</span> rows in <span class="m">1</span>.18s.
dsql&gt;
</code></pre></div>
<p>Let&#39;s look at the three events in the original input data that occurred during <code>2018-01-01T01:01</code>:</p>
<div class="highlight"><pre><code class="language-json" data-lang="json"><span></span><span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-01T01:01:35Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;1.1.1.1&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;2.2.2.2&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">20</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">9024</span><span class="p">}</span>
<span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-01T01:01:51Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;1.1.1.1&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;2.2.2.2&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">255</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">21133</span><span class="p">}</span>
<span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-01T01:01:59Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;1.1.1.1&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;2.2.2.2&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">11</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">5780</span><span class="p">}</span>
</code></pre></div>
<p>These three rows have been &quot;rolled up&quot; into the following row:</p>
<div class="highlight"><pre><code class="language-bash" data-lang="bash"><span></span>┌──────────────────────────┬────────┬───────┬─────────┬─────────┬─────────┐
│ __time │ bytes │ count │ dstIP │ packets │ srcIP │
├──────────────────────────┼────────┼───────┼─────────┼─────────┼─────────┤
<span class="m">2018</span>-01-01T01:01:00.000Z │ <span class="m">35937</span><span class="m">3</span><span class="m">2</span>.2.2.2 │ <span class="m">286</span><span class="m">1</span>.1.1.1 │
└──────────────────────────┴────────┴───────┴─────────┴─────────┴─────────┘
</code></pre></div>
<p>The input rows have been grouped by the timestamp and dimension columns <code>{timestamp, srcIP, dstIP}</code> with sum aggregations on the metric columns <code>packets</code> and <code>bytes</code>.</p>
<p>Before the grouping occurs, the timestamps of the original input data are bucketed/floored by minute, due to the <code>&quot;queryGranularity&quot;:&quot;minute&quot;</code> setting in the ingestion spec.</p>
<p>Likewise, these two events that occurred during <code>2018-01-01T01:02</code> have been rolled up:</p>
<div class="highlight"><pre><code class="language-json" data-lang="json"><span></span><span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-01T01:02:14Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;1.1.1.1&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;2.2.2.2&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">38</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">6289</span><span class="p">}</span>
<span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-01T01:02:29Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;1.1.1.1&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;2.2.2.2&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">377</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">359971</span><span class="p">}</span>
</code></pre></div><div class="highlight"><pre><code class="language-bash" data-lang="bash"><span></span>┌──────────────────────────┬────────┬───────┬─────────┬─────────┬─────────┐
│ __time │ bytes │ count │ dstIP │ packets │ srcIP │
├──────────────────────────┼────────┼───────┼─────────┼─────────┼─────────┤
<span class="m">2018</span>-01-01T01:02:00.000Z │ <span class="m">366260</span><span class="m">2</span><span class="m">2</span>.2.2.2 │ <span class="m">415</span><span class="m">1</span>.1.1.1 │
└──────────────────────────┴────────┴───────┴─────────┴─────────┴─────────┘
</code></pre></div>
<p>For the last event recording traffic between 1.1.1.1 and 2.2.2.2, no roll-up took place, because this was the only event that occurred during <code>2018-01-01T01:03</code>:</p>
<div class="highlight"><pre><code class="language-json" data-lang="json"><span></span><span class="p">{</span><span class="nt">&quot;timestamp&quot;</span><span class="p">:</span><span class="s2">&quot;2018-01-01T01:03:29Z&quot;</span><span class="p">,</span><span class="nt">&quot;srcIP&quot;</span><span class="p">:</span><span class="s2">&quot;1.1.1.1&quot;</span><span class="p">,</span> <span class="nt">&quot;dstIP&quot;</span><span class="p">:</span><span class="s2">&quot;2.2.2.2&quot;</span><span class="p">,</span><span class="nt">&quot;packets&quot;</span><span class="p">:</span><span class="mi">49</span><span class="p">,</span><span class="nt">&quot;bytes&quot;</span><span class="p">:</span><span class="mi">10204</span><span class="p">}</span>
</code></pre></div><div class="highlight"><pre><code class="language-bash" data-lang="bash"><span></span>┌──────────────────────────┬────────┬───────┬─────────┬─────────┬─────────┐
│ __time │ bytes │ count │ dstIP │ packets │ srcIP │
├──────────────────────────┼────────┼───────┼─────────┼─────────┼─────────┤
<span class="m">2018</span>-01-01T01:03:00.000Z │ <span class="m">10204</span><span class="m">1</span><span class="m">2</span>.2.2.2 │ <span class="m">49</span><span class="m">1</span>.1.1.1 │
└──────────────────────────┴────────┴───────┴─────────┴─────────┴─────────┘
</code></pre></div>
<p>Note that the <code>count</code> metric shows how many rows in the original input data contributed to the final &quot;rolled up&quot; row.</p>
</div>
<div class="col-md-3">
<div class="searchbox">
<gcse:searchbox-only></gcse:searchbox-only>
</div>
<div id="toc" class="nav toc hidden-print">
</div>
</div>
</div>
</div>
<!-- Start page_footer include -->
<footer class="druid-footer">
<div class="container">
<div class="text-center">
<p>
<a href="/technology">Technology</a>&ensp;·&ensp;
<a href="/use-cases">Use Cases</a>&ensp;·&ensp;
<a href="/druid-powered">Powered by Druid</a>&ensp;·&ensp;
<a href="/docs/latest/">Docs</a>&ensp;·&ensp;
<a href="/community/">Community</a>&ensp;·&ensp;
<a href="/downloads.html">Download</a>&ensp;·&ensp;
<a href="/faq">FAQ</a>
</p>
</div>
<div class="text-center">
<a title="Join the user group" href="https://groups.google.com/forum/#!forum/druid-user" target="_blank"><span class="fa fa-comments"></span></a>&ensp;·&ensp;
<a title="Follow Druid" href="https://twitter.com/druidio" target="_blank"><span class="fab fa-twitter"></span></a>&ensp;·&ensp;
<a title="GitHub" href="https://github.com/apache/druid" target="_blank"><span class="fab fa-github"></span></a>
</div>
<div class="text-center license">
Copyright © 2020 <a href="https://www.apache.org/" target="_blank">Apache Software Foundation</a>.<br>
Except where otherwise noted, licensed under <a rel="license" href="http://creativecommons.org/licenses/by-sa/4.0/">CC BY-SA 4.0</a>.<br>
Apache Druid, Druid, and the Druid logo are either registered trademarks or trademarks of The Apache Software Foundation in the United States and other countries.
</div>
</div>
</footer>
<script async src="https://www.googletagmanager.com/gtag/js?id=UA-131010415-1"></script>
<script>
window.dataLayer = window.dataLayer || [];
function gtag(){dataLayer.push(arguments);}
gtag('js', new Date());
gtag('config', 'UA-131010415-1');
</script>
<script>
function trackDownload(type, url) {
ga('send', 'event', 'download', type, url);
}
</script>
<script src="//code.jquery.com/jquery.min.js"></script>
<script src="//maxcdn.bootstrapcdn.com/bootstrap/3.2.0/js/bootstrap.min.js"></script>
<script src="/assets/js/druid.js"></script>
<!-- stop page_footer include -->
<script>
$(function() {
$(".toc").load("/docs/0.14.2-incubating/toc.html");
// There is no way to tell when .gsc-input will be async loaded into the page so just try to set a placeholder until it works
var tries = 0;
var timer = setInterval(function() {
tries++;
if (tries > 300) clearInterval(timer);
var searchInput = $('input.gsc-input');
if (searchInput.length) {
searchInput.attr('placeholder', 'Search');
clearInterval(timer);
}
}, 100);
});
</script>
</body>
</html>