Overview

series_acos

You use series_acos when you want to apply trigonometric analysis over time series or other numeric array data. This is useful in cases where your data is stored as arrays, such as time-binned metrics, periodic request patterns, or wave-like behaviors in telemetry data.

Usage#

Syntax#

series_acos(array)

Parameters#

Parameter Type Description
array dynamic A dynamic array of numeric values where each element is between -1 and 1.

Returns#

A dynamic array of the same length as the input where each element is the arc cosine of the corresponding input element. The result values are in radians, in the range [0, π].

Use case examples#

You can analyze the periodicity of request durations. By applying series_acos to normalized values, you reveal inverse cosine transformations that are useful in signal-style analysis of request patterns.

Query

['sample-http-logs']
| summarize durations = make_list(req_duration_ms, 100) by id
| extend normalized = series_acos(durations)

Run in Playground

Output

id durations normalized
U123 [100, 200, 300, 400] [1.47, 1.37, 1.27, 1.16]

The query computes request duration arrays for each user, normalizes them, and applies the inverse cosine function element-wise.

You can transform span durations into the arc cosine space to analyze relationships between services in a trigonometric context, for example for anomaly detection.

Query

['otel-demo-traces']
| summarize spans = make_list(duration, 50) by ['service.name']
| extend acos_spans = series_acos(spans)

Run in Playground

Output

service.name spans acos_spans
frontend [20ms, 40ms, 60ms] [1.55, 1.52, 1.50]

The query groups spans by service and applies the arc cosine transformation to each duration.

You can analyze request patterns by status code. By transforming request durations into arc cosine values, you can highlight cyclical or anomalous activity.

Query

['sample-http-logs']
| where status == '200'
| summarize durations = make_list(req_duration_ms, 100) by ['geo.country']
| extend acos_durations = series_acos(durations)

Run in Playground

Output

geo.country durations acos_durations
US [120, 180, 240, 300] [1.47, 1.38, 1.29, 1.21]

The query focuses on successful requests, aggregates their durations by country, and applies the arc cosine function to detect unusual duration distributions.

  • series_asin: Applies the arc sine function element-wise to array values. Use this when you need the inverse sine instead of the inverse cosine.
  • series_atan: Applies the arc tangent function element-wise to array values. Use this when analyzing angular relationships that use tangent ratios.

Other query languages#

Splunk SPL users

Splunk SPL doesn’t provide a direct acos function for array values. You typically need to expand multivalue fields into individual events, apply the acos() function to each event, and then optionally collect the results back into an array. In APL, series_acos applies the function element-wise to a dynamic array in one step.

Splunk example

... | eval acos_value = mvmap(my_array, acos(x))

APL equivalent

datatable(arr: dynamic)
[
  dynamic([0.1, 0.5, 1.0])
]
| extend acos_arr = series_acos(arr)
ANSI SQL users

ANSI SQL provides the ACOS() scalar function for individual numeric values but does not support arrays as a native type. To work with multiple values, you usually normalize data into rows and apply ACOS() row by row. In APL, series_acos lets you apply the function directly to arrays without unnesting them.

SQL example

SELECT ACOS(value)
FROM numbers;

APL equivalent

datatable(arr: dynamic)
[
  dynamic([0.1, 0.5, 1.0])
]
| extend acos_arr = series_acos(arr)

Updated

Was this page helpful?