Overview

series_abs

You can use series_abs when you want to normalize data and remove the effect of directionality. For example, it’s useful in time-series scenarios where you want to analyze the magnitude of changes regardless of whether they’re positive or negative. Typical applications include error analysis, performance monitoring, and anomaly detection.

Usage#

Syntax#

series_abs(array)

Parameters#

Parameter Type Description
array dynamic A dynamic array of numeric values.

Returns#

A dynamic array where each element is the absolute value of the corresponding input element.

Use case examples#

In log analysis, you can use series_abs to analyze request durations by focusing on their magnitude, regardless of whether values are represented as positive or negative deviations.

Query

['sample-http-logs']
| summarize durations = make_list(req_duration_ms) by id
| extend abs_durations = series_abs(durations)

Run in Playground

Output

id durations abs_durations
u123 [-50, 30, -10, 20] [50, 30, 10, 20]
u456 [5, -7, -3, 9] [5, 7, 3, 9]

This query collects request durations for each user, then converts them into absolute values for magnitude-based analysis.

In OpenTelemetry traces, you can use series_abs to evaluate span durations as absolute values when analyzing deviations.

Query

['otel-demo-traces']
| summarize durations = make_list(duration) by ['service.name']
| extend abs_durations = series_abs(durations)

Run in Playground

Output

service.name durations abs_durations
frontend [-200ms, 300ms, -100ms] [200ms, 300ms, 100ms]
productcatalogservice [50ms, -80ms, 120ms] [50ms, 80ms, 120ms]

This query aggregates span durations per service and applies series_abs to analyze absolute values of latencies.

In security logs, you can use series_abs to normalize anomalous request durations before analyzing request patterns.

Query

['sample-http-logs']
| summarize durations = make_list(req_duration_ms) by status
| extend abs_durations = series_abs(durations)

Run in Playground

Output

status durations abs_durations
200 [-10, 15, -20, 5] [10, 15, 20, 5]
500 [25, -40, -35, 30] [25, 40, 35, 30]

This query groups request durations by status code and applies series_abs to focus on the magnitude of request times.

  • series_acos: Returns the arc cosine of each element in an array. Use when you need to invert cosine transformations instead of sine.
  • series_asin: Applies the arc sine function element-wise to array values. Use this when you need the inverse sine instead of the inverse cosine.
  • series_atan: Returns the arc tangent of each element in an array. Useful for handling tangent-derived data.

Other query languages#

Splunk SPL users

In Splunk SPL, absolute values are usually calculated with the eval function and the abs() expression. In APL, you apply series_abs to an array column to calculate absolute values for all elements in one step.

Splunk example

... | eval abs_duration=abs(duration)

APL equivalent

datatable(x: dynamic)
[
  dynamic([-2, -1, 0, 1, 2])
]
| extend abs_values = series_abs(x)
ANSI SQL users

In SQL, you calculate absolute values with the ABS() scalar function, but this only applies to single values, not arrays. In APL, series_abs applies the operation to every element in a dynamic array, which makes it convenient for series analysis.

SQL example

SELECT ABS(duration) AS abs_duration
FROM requests;

APL equivalent

datatable(x: dynamic)
[
  dynamic([-2, -1, 0, 1, 2])
]
| extend abs_values = series_abs(x)

Updated

Was this page helpful?