series_abs
You can use series_abs when you want to normalize data and remove the effect of directionality. For example, it’s useful in time-series scenarios where you want to analyze the magnitude of changes regardless of whether they’re positive or negative. Typical applications include error analysis, performance monitoring, and anomaly detection.
Usage#
Syntax#
series_abs(array)Parameters#
| Parameter | Type | Description |
|---|---|---|
array |
dynamic | A dynamic array of numeric values. |
Returns#
A dynamic array where each element is the absolute value of the corresponding input element.
Use case examples#
In log analysis, you can use series_abs to analyze request durations by focusing on their magnitude, regardless of whether values are represented as positive or negative deviations.
Query
['sample-http-logs']
| summarize durations = make_list(req_duration_ms) by id
| extend abs_durations = series_abs(durations)Output
| id | durations | abs_durations |
|---|---|---|
| u123 | [-50, 30, -10, 20] | [50, 30, 10, 20] |
| u456 | [5, -7, -3, 9] | [5, 7, 3, 9] |
This query collects request durations for each user, then converts them into absolute values for magnitude-based analysis.
In OpenTelemetry traces, you can use series_abs to evaluate span durations as absolute values when analyzing deviations.
Query
['otel-demo-traces']
| summarize durations = make_list(duration) by ['service.name']
| extend abs_durations = series_abs(durations)Output
| service.name | durations | abs_durations |
|---|---|---|
| frontend | [-200ms, 300ms, -100ms] | [200ms, 300ms, 100ms] |
| productcatalogservice | [50ms, -80ms, 120ms] | [50ms, 80ms, 120ms] |
This query aggregates span durations per service and applies series_abs to analyze absolute values of latencies.
In security logs, you can use series_abs to normalize anomalous request durations before analyzing request patterns.
Query
['sample-http-logs']
| summarize durations = make_list(req_duration_ms) by status
| extend abs_durations = series_abs(durations)Output
| status | durations | abs_durations |
|---|---|---|
| 200 | [-10, 15, -20, 5] | [10, 15, 20, 5] |
| 500 | [25, -40, -35, 30] | [25, 40, 35, 30] |
This query groups request durations by status code and applies series_abs to focus on the magnitude of request times.
List of related functions#
- series_acos: Returns the arc cosine of each element in an array. Use when you need to invert cosine transformations instead of sine.
- series_asin: Applies the arc sine function element-wise to array values. Use this when you need the inverse sine instead of the inverse cosine.
- series_atan: Returns the arc tangent of each element in an array. Useful for handling tangent-derived data.
Other query languages#
Splunk SPL users
In Splunk SPL, absolute values are usually calculated with the eval function and the abs() expression. In APL, you apply series_abs to an array column to calculate absolute values for all elements in one step.
Splunk example
... | eval abs_duration=abs(duration)APL equivalent
datatable(x: dynamic)
[
dynamic([-2, -1, 0, 1, 2])
]
| extend abs_values = series_abs(x)ANSI SQL users
In SQL, you calculate absolute values with the ABS() scalar function, but this only applies to single values, not arrays. In APL, series_abs applies the operation to every element in a dynamic array, which makes it convenient for series analysis.
SQL example
SELECT ABS(duration) AS abs_duration
FROM requests;APL equivalent
datatable(x: dynamic)
[
dynamic([-2, -1, 0, 1, 2])
]
| extend abs_values = series_abs(x)