[{"data":1,"prerenderedAt":2116},["ShallowReactive",2],{"\u002Ffeatures\u002Ftraces\u002Freference-navigation":3,"\u002Ffeatures\u002Ftraces\u002Freference":146},[4,8,32,42,59,77,81,85,95,104,108,112,116,120,124,128],{"title":5,"path":6,"stem":7},"Get started","\u002Ffeatures","features\u002Findex",{"title":9,"closed":10,"path":11,"stem":12,"children":13,"page":-1},"Traces",true,"\u002Ffeatures\u002Ftraces","features\u002F01.traces\u002Findex",[14,16,20,24,28],{"title":15,"path":11,"stem":12},"Introduction",{"title":17,"path":18,"stem":19},"Grouping & systems","\u002Ffeatures\u002Ftraces\u002Fgrouping","features\u002F01.traces\u002F02.grouping",{"title":21,"path":22,"stem":23},"Querying spans","\u002Ffeatures\u002Ftraces\u002Fquerying-spans","features\u002F01.traces\u002F03.querying-spans",{"title":25,"path":26,"stem":27},"Querying traces","\u002Ffeatures\u002Ftraces\u002Fquerying-traces","features\u002F01.traces\u002F04.querying-traces",{"title":29,"path":30,"stem":31},"Reference","\u002Ffeatures\u002Ftraces\u002Freference","features\u002F01.traces\u002F05.reference",{"title":33,"closed":10,"path":34,"stem":35,"children":36,"page":-1},"Logs","\u002Ffeatures\u002Flogs","features\u002F02.logs\u002Findex",[37,38],{"title":15,"path":34,"stem":35},{"title":39,"path":40,"stem":41},"Grouping rules","\u002Ffeatures\u002Flogs\u002Fgrouping","features\u002F02.logs\u002Fgrouping",{"title":43,"closed":10,"path":44,"stem":45,"children":46,"page":-1},"Metrics","\u002Ffeatures\u002Fmetrics","features\u002F03.metrics\u002Findex",[47,48,52,56],{"title":15,"path":44,"stem":45},{"title":49,"path":50,"stem":51},"Querying","\u002Ffeatures\u002Fmetrics\u002Fquerying","features\u002F03.metrics\u002F02.querying",{"title":53,"path":54,"stem":55},"PromQL compat","\u002Ffeatures\u002Fmetrics\u002Fpromql-compat","features\u002F03.metrics\u002F03.promql-compat",{"title":29,"path":57,"stem":58},"\u002Ffeatures\u002Fmetrics\u002Freference","features\u002F03.metrics\u002F04.reference",{"title":60,"closed":10,"path":61,"stem":62,"children":63,"page":-1},"Alerting","\u002Ffeatures\u002Falerting","features\u002F04.alerting\u002Findex",[64,65,69,73],{"title":15,"path":61,"stem":62},{"title":66,"path":67,"stem":68},"Error monitors","\u002Ffeatures\u002Falerting\u002Ferror-monitors","features\u002F04.alerting\u002Ferror-monitors",{"title":70,"path":71,"stem":72},"Metric monitors","\u002Ffeatures\u002Falerting\u002Fmetric-monitors","features\u002F04.alerting\u002Fmetric-monitors",{"title":74,"path":75,"stem":76},"Notifications","\u002Ffeatures\u002Falerting\u002Fnotifications","features\u002F04.alerting\u002Fnotifications",{"title":78,"path":79,"stem":80},"Searching","\u002Ffeatures\u002Fsearching","features\u002F04.searching",{"title":82,"path":83,"stem":84},"Chart Annotations","\u002Ffeatures\u002Fannotations","features\u002F05.annotations",{"title":86,"path":87,"stem":88,"children":89,"closed":10},"Dashboards","\u002Ffeatures\u002Fdashboards","features\u002F06.dashboards\u002F01.index",[90,91],{"title":86,"path":87,"stem":88},{"title":92,"path":93,"stem":94},"YAML Templates","\u002Ffeatures\u002Fdashboards\u002Fyaml","features\u002F06.dashboards\u002F02.yaml",{"title":96,"path":97,"stem":98,"children":99,"closed":10},"Transformations","\u002Ffeatures\u002Ftransformations","features\u002F07.transformations\u002F01.index",[100,101],{"title":15,"path":97,"stem":98},{"title":29,"path":102,"stem":103},"\u002Ffeatures\u002Ftransformations\u002Freference","features\u002F07.transformations\u002F02.reference",{"title":105,"path":106,"stem":107},"Service Graph","\u002Ffeatures\u002Fservice-graph","features\u002F08.service-graph",{"title":109,"path":110,"stem":111},"Grafana integration","\u002Ffeatures\u002Fgrafana","features\u002F09.grafana",{"title":113,"path":114,"stem":115},"Data fixtures","\u002Ffeatures\u002Ffixtures","features\u002F10.fixtures",{"title":117,"path":118,"stem":119},"JavaScript Source Maps","\u002Ffeatures\u002Fsourcemaps","features\u002F11.sourcemaps",{"title":121,"path":122,"stem":123},"MCP Server","\u002Ffeatures\u002Fmcp","features\u002F12.mcp",{"title":125,"path":126,"stem":127},"Observability as Code","\u002Ffeatures\u002Fobservability-as-code","features\u002F13.observability-as-code",{"title":129,"closed":10,"path":130,"stem":131,"children":132,"page":145},"SSO","\u002Ffeatures\u002Fsso","features\u002Fsso",[133,137,141],{"title":134,"path":135,"stem":136},"Google","\u002Ffeatures\u002Fsso\u002Fgoogle","features\u002Fsso\u002F01.google",{"title":138,"path":139,"stem":140},"Okta","\u002Ffeatures\u002Fsso\u002Fokta","features\u002Fsso\u002F02.okta",{"title":142,"path":143,"stem":144},"Keycloak","\u002Ffeatures\u002Fsso\u002Fkeycloak","features\u002Fsso\u002F03.keycloak",false,{"page":147,"surround":2111},{"id":148,"title":149,"author":150,"body":151,"date":150,"description":2100,"extension":2101,"image":150,"meta":2102,"navigation":2108,"path":30,"seo":2109,"stem":31,"surround_disabled":145,"__hash__":2110},"features\u002Ffeatures\u002F01.traces\u002F05.reference.md","Span query language reference",null,{"type":152,"value":153,"toc":2078},"minimark",[154,165,173,211,216,226,478,498,502,505,620,623,636,639,644,683,687,703,722,726,817,827,886,890,1106,1114,1134,1138,1145,1202,1205,1209,1212,1237,1241,1244,1248,1330,1380,1384,1428,1437,1458,1462,1504,1507,1511,1533,1558,1562,1565,1648,1673,1677,1680,1683,1734,1737,1887,1930,1932,1939,2009,2017,2046,2050,2074],[155,156,157,158,161,162,164],"p",{},"This page lists every field, function, operator, and search operator the Uptrace span query language accepts. The language works on spans, logs, and events. To learn how to write queries, start with ",[159,160,21],"a",{"href":22},"; to select whole traces, see ",[159,163,25],{"href":26},".",[155,166,167,168,172],{},"A query is a list of clauses separated by ",[169,170,171],"code",{},"|",":",[174,175,180],"pre",{"className":176,"code":177,"language":178,"meta":179,"style":179},"language-sql shiki shiki-themes github-light","group by service_name | p50(_dur_ms) | where _status_code = 'error'\n","sql","",[169,181,182],{"__ignoreMap":179},[183,184,187,191,194,198,201,204,207],"span",{"class":185,"line":186},"line",1,[183,188,190],{"class":189},"sD7c4","group by",[183,192,193],{"class":189}," service_name",[183,195,197],{"class":196},"sgsFI"," | p50(_dur_ms) | ",[183,199,200],{"class":189},"where",[183,202,203],{"class":196}," _status_code ",[183,205,206],{"class":189},"=",[183,208,210],{"class":209},"sYBdl"," 'error'\n",[212,213,215],"h2",{"id":214},"built-in-fields","Built-in fields",[155,217,218,219,222,223,164],{},"A built-in field starts with an underscore, so it cannot collide with an attribute. An attribute name replaces dots with underscores, so ",[169,220,221],{},"service.name"," becomes ",[169,224,225],{},"service_name",[227,228,229,245],"table",{},[230,231,232],"thead",{},[233,234,235,239,242],"tr",{},[236,237,238],"th",{},"Field",[236,240,241],{},"Type",[236,243,244],{},"Description",[246,247,248,262,274,286,298,310,322,337,356,368,380,392,405,418,441,453,466],"tbody",{},[233,249,250,256,259],{},[251,252,253],"td",{},[169,254,255],{},"_id",[251,257,258],{},"str",[251,260,261],{},"The record's own id.",[233,263,264,269,271],{},[251,265,266],{},[169,267,268],{},"_parent_id",[251,270,258],{},[251,272,273],{},"The id of the record's parent span.",[233,275,276,281,283],{},[251,277,278],{},[169,279,280],{},"_trace_id",[251,282,258],{},[251,284,285],{},"The id of the trace the record belongs to.",[233,287,288,293,295],{},[251,289,290],{},[169,291,292],{},"_group_id",[251,294,258],{},[251,296,297],{},"The id of the group the record was fingerprinted into.",[233,299,300,305,307],{},[251,301,302],{},[169,303,304],{},"_grouping_rule_id",[251,306,258],{},[251,308,309],{},"The id of the log grouping rule that assigned the hash.",[233,311,312,317,319],{},[251,313,314],{},[169,315,316],{},"_type",[251,318,258],{},[251,320,321],{},"The coarse category ingest classified the record into.",[233,323,324,329,331],{},[251,325,326],{},[169,327,328],{},"_system",[251,330,258],{},[251,332,333,334,164],{},"The categorization facet derived from the type, for example ",[169,335,336],{},"db:postgresql",[233,338,339,344,346],{},[251,340,341],{},[169,342,343],{},"_kind",[251,345,258],{},[251,347,348,349,352,353,164],{},"The OpenTelemetry span kind, for example ",[169,350,351],{},"server"," or ",[169,354,355],{},"client",[233,357,358,363,365],{},[251,359,360],{},[169,361,362],{},"_name",[251,364,258],{},[251,366,367],{},"The raw span name, which grouping uses.",[233,369,370,375,377],{},[251,371,372],{},[169,373,374],{},"_event_name",[251,376,258],{},[251,378,379],{},"The OpenTelemetry event name, for a span event.",[233,381,382,387,389],{},[251,383,384],{},[169,385,386],{},"_display_name",[251,388,258],{},[251,390,391],{},"The human-facing label ingest computed.",[233,393,394,399,402],{},[251,395,396],{},[169,397,398],{},"_time",[251,400,401],{},"time",[251,403,404],{},"The time the record started, with microsecond accuracy.",[233,406,407,412,415],{},[251,408,409],{},[169,410,411],{},"_dur_ms",[251,413,414],{},"float",[251,416,417],{},"The record's duration in milliseconds.",[233,419,420,425,427],{},[251,421,422],{},[169,423,424],{},"_status_code",[251,426,258],{},[251,428,429,430,433,434,437,438,164],{},"The record's status code: ",[169,431,432],{},"ok",", ",[169,435,436],{},"error",", or ",[169,439,440],{},"unset",[233,442,443,448,450],{},[251,444,445],{},[169,446,447],{},"_status_message",[251,449,258],{},[251,451,452],{},"The record's status message.",[233,454,455,460,463],{},[251,456,457],{},[169,458,459],{},"_error_count",[251,461,462],{},"int",[251,464,465],{},"The number of errors the record counts.",[233,467,468,473,475],{},[251,469,470],{},[169,471,472],{},"_error_rate",[251,474,414],{},[251,476,477],{},"The share of records that are errors, as a ratio of two counts.",[479,480,482],"alert",{"type":481},"info",[155,483,484,486,487,490,491,494,495,497],{},[169,485,411],{}," accepts two aliases: ",[169,488,489],{},"_duration"," and ",[169,492,493],{},"_dur",". The parser normalizes both to ",[169,496,411],{},", so the three spellings are the same field.",[212,499,501],{"id":500},"data-types","Data types",[155,503,504],{},"Uptrace discovers an attribute's type from the data. Each type accepts its own comparison operators:",[227,506,507,516],{},[230,508,509],{},[233,510,511,513],{},[236,512,241],{},[236,514,515],{},"Operators",[246,517,518,550,578,591,604],{},[233,519,520,524],{},[251,521,522],{},[169,523,258],{},[251,525,526,433,528,433,531,433,534,433,537,433,540,433,543,546,547],{},[169,527,206],{},[169,529,530],{},"!=",[169,532,533],{},"in",[169,535,536],{},"like",[169,538,539],{},"not like",[169,541,542],{},"contains",[169,544,545],{},"~"," (regexp), ",[169,548,549],{},"exists",[233,551,552,558],{},[251,553,554,490,556],{},[169,555,462],{},[169,557,414],{},[251,559,560,433,562,433,564,433,567,433,570,433,573,433,576],{},[169,561,206],{},[169,563,530],{},[169,565,566],{},"\u003C",[169,568,569],{},"\u003C=",[169,571,572],{},">",[169,574,575],{},">=",[169,577,549],{},[233,579,580,585],{},[251,581,582],{},[169,583,584],{},"bool",[251,586,587,433,589],{},[169,588,206],{},[169,590,530],{},[233,592,593,598],{},[251,594,595],{},[169,596,597],{},"[]str",[251,599,600,433,602],{},[169,601,542],{},[169,603,549],{},[233,605,606,610],{},[251,607,608],{},[169,609,401],{},[251,611,612,433,614,433,616,433,618],{},[169,613,566],{},[169,615,569],{},[169,617,572],{},[169,619,575],{},[155,621,622],{},"Annotate a type when discovery is not enough, which happens when one attribute holds different types across records:",[174,624,626],{"className":176,"code":625,"language":178,"meta":179,"style":179},"foo::string | foo::int\n",[169,627,628],{"__ignoreMap":179},[183,629,630,633],{"class":185,"line":186},[183,631,632],{"class":196},"foo::string | foo::",[183,634,635],{"class":189},"int\n",[155,637,638],{},"Uptrace uses the annotation as a hint for reading columnar data. It does not convert the value.",[640,641,643],"h3",{"id":642},"string-literals","String literals",[174,645,647],{"className":176,"code":646,"language":178,"meta":179,"style":179},"\"I'm a string\\n\"           -- double quotes, with escape sequences\n'I\\'m a string\\n'          -- single quotes, with escape sequences\n`^some-prefix-(\\w+)$`      -- backticks, no escape sequences, for a regexp\n",[169,648,649,658,670],{"__ignoreMap":179},[183,650,651,654],{"class":185,"line":186},[183,652,653],{"class":209},"\"I'm a string\\n\"",[183,655,657],{"class":656},"sAwPA","           -- double quotes, with escape sequences\n",[183,659,661,664,667],{"class":185,"line":660},2,[183,662,663],{"class":209},"'I\\'",[183,665,666],{"class":196},"m a string\\n",[183,668,669],{"class":209},"'          -- single quotes, with escape sequences\n",[183,671,673,676,680],{"class":185,"line":672},3,[183,674,675],{"class":209},"`^some-prefix-(",[183,677,679],{"class":678},"sYu0t","\\w",[183,681,682],{"class":209},"+)$`      -- backticks, no escape sequences, for a regexp\n",[640,684,686],{"id":685},"units","Units",[155,688,689,690,433,693,433,696,433,699,702],{},"Uptrace reads a unit from a name suffix, and then formats the column for you: ",[169,691,692],{},"bytes",[169,694,695],{},"seconds",[169,697,698],{},"milliseconds",[169,700,701],{},"utilization",". When you cannot rename the attribute, alias the expression:",[174,704,706],{"className":176,"code":705,"language":178,"meta":179,"style":179},"sum(heap_size) as heap_size_bytes\n",[169,707,708],{"__ignoreMap":179},[183,709,710,713,716,719],{"class":185,"line":186},[183,711,712],{"class":678},"sum",[183,714,715],{"class":196},"(heap_size) ",[183,717,718],{"class":189},"as",[183,720,721],{"class":196}," heap_size_bytes\n",[212,723,725],{"id":724},"clauses","Clauses",[227,727,728,740],{},[230,729,730],{},[233,731,732,735,738],{},[236,733,734],{},"Clause",[236,736,737],{},"Example",[236,739,244],{},[246,741,742,757,771,785,800],{},[233,743,744,749,754],{},[251,745,746],{},[169,747,748],{},"select",[251,750,751],{},[169,752,753],{},"select count(), p50(_dur_ms)",[251,755,756],{},"Names the result columns. The keyword is optional, so a bare expression is a selector too.",[233,758,759,763,768],{},[251,760,761],{},[169,762,200],{},[251,764,765],{},[169,766,767],{},"where _status_code = 'error'",[251,769,770],{},"Filters records before grouping.",[233,772,773,777,782],{},[251,774,775],{},[169,776,190],{},[251,778,779],{},[169,780,781],{},"group by service_name, host_name",[251,783,784],{},"Groups records, and adds the columns to the result.",[233,786,787,792,797],{},[251,788,789],{},[169,790,791],{},"having",[251,793,794],{},[169,795,796],{},"having p50(_dur_ms) > 100ms",[251,798,799],{},"Filters the groups after aggregation.",[233,801,802,805,810],{},[251,803,804],{},"search",[251,806,807],{},[169,808,809],{},"error -timeout",[251,811,812,813,164],{},"Free-text search — see ",[159,814,816],{"href":815},"#search","Search syntax",[155,818,819,820,822,823,172],{},"Rename a grouping column with ",[169,821,718],{},", and manipulate its value with a ",[159,824,826],{"href":825},"#transform","transform function",[174,828,830],{"className":176,"code":829,"language":178,"meta":179,"style":179},"group by lower(service_name) as service, upper(host_name) as host\ngroup by extract(host_name, `^uptrace-prod-(\\w+)$`) as host\n",[169,831,832,865],{"__ignoreMap":179},[183,833,834,836,839,842,844,847,849,852,854,857,860,862],{"class":185,"line":186},[183,835,190],{"class":189},[183,837,838],{"class":678}," lower",[183,840,841],{"class":196},"(",[183,843,225],{"class":189},[183,845,846],{"class":196},") ",[183,848,718],{"class":189},[183,850,851],{"class":189}," service",[183,853,433],{"class":196},[183,855,856],{"class":678},"upper",[183,858,859],{"class":196},"(host_name) ",[183,861,718],{"class":189},[183,863,864],{"class":196}," host\n",[183,866,867,869,872,875,877,880,882,884],{"class":185,"line":660},[183,868,190],{"class":189},[183,870,871],{"class":196}," extract(host_name, ",[183,873,874],{"class":209},"`^uptrace-prod-(",[183,876,679],{"class":678},[183,878,879],{"class":209},"+)$`",[183,881,846],{"class":196},[183,883,718],{"class":189},[183,885,864],{"class":196},[212,887,889],{"id":888},"aggregate-functions","Aggregate functions",[227,891,892,901],{},[230,893,894],{},[233,895,896,899],{},[236,897,898],{},"Function",[236,900,244],{},[246,902,903,913,926,936,946,956,966,976,986,996,1018,1035,1045,1055,1068,1094],{},[233,904,905,910],{},[251,906,907],{},[169,908,909],{},"count()",[251,911,912],{},"Number of matched records. Takes no arguments.",[233,914,915,920],{},[251,916,917],{},[169,918,919],{},"countAll()",[251,921,922,923,925],{},"Same as ",[169,924,909],{},": both count every record a pre-aggregated row weighs.",[233,927,928,933],{},[251,929,930],{},[169,931,932],{},"countDistinct()",[251,934,935],{},"Number of distinct records. Takes no arguments.",[233,937,938,943],{},[251,939,940],{},[169,941,942],{},"uniq(attr)",[251,944,945],{},"Number of distinct values of the attribute.",[233,947,948,953],{},[251,949,950],{},[169,951,952],{},"sum(attr)",[251,954,955],{},"Sum of the values.",[233,957,958,963],{},[251,959,960],{},[169,961,962],{},"avg(attr)",[251,964,965],{},"Average of the values.",[233,967,968,973],{},[251,969,970],{},[169,971,972],{},"min(attr)",[251,974,975],{},"Smallest value.",[233,977,978,983],{},[251,979,980],{},[169,981,982],{},"max(attr)",[251,984,985],{},"Largest value.",[233,987,988,993],{},[251,989,990],{},[169,991,992],{},"median(attr)",[251,994,995],{},"Median of the values.",[233,997,998,1003],{},[251,999,1000],{},[169,1001,1002],{},"p50(attr)",[251,1004,1005,1006,433,1009,433,1012,433,1015,164],{},"50th percentile. Also ",[169,1007,1008],{},"p75",[169,1010,1011],{},"p90",[169,1013,1014],{},"p95",[169,1016,1017],{},"p99",[233,1019,1020,1025],{},[251,1021,1022],{},[169,1023,1024],{},"quantile(level, attr)",[251,1026,1027,1028,1031,1032,164],{},"Quantile at an arbitrary ",[169,1029,1030],{},"level",", for example ",[169,1033,1034],{},"quantile(0.8, _dur_ms)",[233,1036,1037,1042],{},[251,1038,1039],{},[169,1040,1041],{},"any(attr)",[251,1043,1044],{},"An arbitrary value from the group.",[233,1046,1047,1052],{},[251,1048,1049],{},[169,1050,1051],{},"anyLast(attr)",[251,1053,1054],{},"The last value in the group.",[233,1056,1057,1062],{},[251,1058,1059],{},[169,1060,1061],{},"top3(attr)",[251,1063,1064,1065,164],{},"The three most frequent values, as an array. Also ",[169,1066,1067],{},"top10",[233,1069,1070,1075],{},[251,1071,1072],{},[169,1073,1074],{},"apdex(t1, t2)",[251,1076,1077,1083,1084,1087,1088,1031,1091,164],{},[159,1078,1082],{"href":1079,"rel":1080},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FApdex",[1081],"nofollow","Apdex"," score of span duration, with a satisfied threshold ",[169,1085,1086],{},"t1"," and a tolerating threshold ",[169,1089,1090],{},"t2",[169,1092,1093],{},"apdex(500ms, 3s)",[233,1095,1096,1101],{},[251,1097,1098],{},[169,1099,1100],{},"merge(agg($alias.attr))",[251,1102,1103,1104,164],{},"Re-aggregates the per-trace partials of a cross-join expression — see ",[159,1105,25],{"href":26},[155,1107,1108,1110,1111,1113],{},[169,1109,909],{}," counts records, and ",[169,1112,942],{}," counts distinct values of an attribute. To count affected users in each group of errors:",[174,1115,1117],{"className":176,"code":1116,"language":178,"meta":179,"style":179},"group by _group_id | uniq(enduser_id) | where _status_code = 'error'\n",[169,1118,1119],{"__ignoreMap":179},[183,1120,1121,1123,1126,1128,1130,1132],{"class":185,"line":186},[183,1122,190],{"class":189},[183,1124,1125],{"class":196}," _group_id | uniq(enduser_id) | ",[183,1127,200],{"class":189},[183,1129,203],{"class":196},[183,1131,206],{"class":189},[183,1133,210],{"class":209},[640,1135,1137],{"id":1136},"conditional-aggregates","Conditional aggregates",[155,1139,1140,1141,1144],{},"Add the ",[169,1142,1143],{},"If"," suffix to any aggregate to pass a condition as its last argument. The aggregate then reads only the records the condition matches:",[174,1146,1148],{"className":176,"code":1147,"language":178,"meta":179,"style":179},"countIf(_status_code = \"error\")\nsumIf(http_request_content_length, _kind = \"server\")\np50If(_dur_ms, service_name = \"api\")\nuniqIf(enduser_id, _status_code = \"error\")\n",[169,1149,1150,1163,1175,1190],{"__ignoreMap":179},[183,1151,1152,1155,1157,1160],{"class":185,"line":186},[183,1153,1154],{"class":196},"countIf(_status_code ",[183,1156,206],{"class":189},[183,1158,1159],{"class":209}," \"error\"",[183,1161,1162],{"class":196},")\n",[183,1164,1165,1168,1170,1173],{"class":185,"line":660},[183,1166,1167],{"class":196},"sumIf(http_request_content_length, _kind ",[183,1169,206],{"class":189},[183,1171,1172],{"class":209}," \"server\"",[183,1174,1162],{"class":196},[183,1176,1177,1180,1182,1185,1188],{"class":185,"line":672},[183,1178,1179],{"class":196},"p50If(_dur_ms, ",[183,1181,225],{"class":189},[183,1183,1184],{"class":189}," =",[183,1186,1187],{"class":209}," \"api\"",[183,1189,1162],{"class":196},[183,1191,1193,1196,1198,1200],{"class":185,"line":1192},4,[183,1194,1195],{"class":196},"uniqIf(enduser_id, _status_code ",[183,1197,206],{"class":189},[183,1199,1159],{"class":209},[183,1201,1162],{"class":196},[155,1203,1204],{},"The suffix works for every aggregate, and it requires at least one argument.",[640,1206,1208],{"id":1207},"virtual-columns","Virtual columns",[155,1210,1211],{},"A virtual column is a shortcut for a common expression:",[227,1213,1214,1224],{},[230,1215,1216],{},[233,1217,1218,1221],{},[236,1219,1220],{},"Column",[236,1222,1223],{},"The same as",[246,1225,1226],{},[233,1227,1228,1232],{},[251,1229,1230],{},[169,1231,472],{},[251,1233,1234],{},[169,1235,1236],{},"countIf(_status_code = \"error\") \u002F count()",[212,1238,1240],{"id":1239},"transform","Transform functions",[155,1242,1243],{},"A transform function returns a new value for each record. Use one in a grouping expression, a filter, or an aggregate's argument.",[640,1245,1247],{"id":1246},"strings","Strings",[227,1249,1250,1258],{},[230,1251,1252],{},[233,1253,1254,1256],{},[236,1255,898],{},[236,1257,244],{},[246,1259,1260,1270,1280,1290,1300,1310,1320],{},[233,1261,1262,1267],{},[251,1263,1264],{},[169,1265,1266],{},"lower(attr)",[251,1268,1269],{},"Converts the value to lowercase.",[233,1271,1272,1277],{},[251,1273,1274],{},[169,1275,1276],{},"upper(attr)",[251,1278,1279],{},"Converts the value to uppercase.",[233,1281,1282,1287],{},[251,1283,1284],{},[169,1285,1286],{},"trimPrefix(attr, \"prefix\")",[251,1288,1289],{},"Removes the leading prefix.",[233,1291,1292,1297],{},[251,1293,1294],{},[169,1295,1296],{},"trimSuffix(attr, \"suffix\")",[251,1298,1299],{},"Removes the trailing suffix.",[233,1301,1302,1307],{},[251,1303,1304],{},[169,1305,1306],{},"extract(attr, pattern)",[251,1308,1309],{},"Extracts the part the regexp captures.",[233,1311,1312,1317],{},[251,1313,1314],{},[169,1315,1316],{},"replace(attr, substring, replacement)",[251,1318,1319],{},"Replaces every occurrence of the substring.",[233,1321,1322,1327],{},[251,1323,1324],{},[169,1325,1326],{},"replaceRegexp(attr, pattern, replacement)",[251,1328,1329],{},"Replaces every part that matches the regexp.",[174,1331,1333],{"className":176,"code":1332,"language":178,"meta":179,"style":179},"group by replace(host_name, 'uptrace-prod-', '') as host\ngroup by replaceRegexp(host, `^`, 'prefix ') as host\n",[169,1334,1335,1359],{"__ignoreMap":179},[183,1336,1337,1339,1342,1345,1348,1350,1353,1355,1357],{"class":185,"line":186},[183,1338,190],{"class":189},[183,1340,1341],{"class":678}," replace",[183,1343,1344],{"class":196},"(host_name, ",[183,1346,1347],{"class":209},"'uptrace-prod-'",[183,1349,433],{"class":196},[183,1351,1352],{"class":209},"''",[183,1354,846],{"class":196},[183,1356,718],{"class":189},[183,1358,864],{"class":196},[183,1360,1361,1363,1366,1369,1371,1374,1376,1378],{"class":185,"line":660},[183,1362,190],{"class":189},[183,1364,1365],{"class":196}," replaceRegexp(host, ",[183,1367,1368],{"class":209},"`^`",[183,1370,433],{"class":196},[183,1372,1373],{"class":209},"'prefix '",[183,1375,846],{"class":196},[183,1377,718],{"class":189},[183,1379,864],{"class":196},[640,1381,1383],{"id":1382},"rates","Rates",[227,1385,1386,1394],{},[230,1387,1388],{},[233,1389,1390,1392],{},[236,1391,898],{},[236,1393,244],{},[246,1395,1396,1406,1416],{},[233,1397,1398,1403],{},[251,1399,1400],{},[169,1401,1402],{},"perMin(expr)",[251,1404,1405],{},"Divides the value by the number of minutes in the time interval.",[233,1407,1408,1413],{},[251,1409,1410],{},[169,1411,1412],{},"perSec(expr)",[251,1414,1415],{},"Divides the value by the number of seconds in the time interval.",[233,1417,1418,1423],{},[251,1419,1420],{},[169,1421,1422],{},"rate(expr)",[251,1424,922,1425,164],{},[169,1426,1427],{},"perSec",[155,1429,1430,490,1433,1436],{},[169,1431,1432],{},"per_min",[169,1434,1435],{},"per_sec"," are accepted spellings of the first two.",[174,1438,1440],{"className":176,"code":1439,"language":178,"meta":179,"style":179},"perMin(count()) | perSec(count())\n",[169,1441,1442],{"__ignoreMap":179},[183,1443,1444,1447,1450,1453,1455],{"class":185,"line":186},[183,1445,1446],{"class":196},"perMin(",[183,1448,1449],{"class":678},"count",[183,1451,1452],{"class":196},"()) | perSec(",[183,1454,1449],{"class":678},[183,1456,1457],{"class":196},"())\n",[640,1459,1461],{"id":1460},"type-conversion","Type conversion",[227,1463,1464,1472],{},[230,1465,1466],{},[233,1467,1468,1470],{},[236,1469,898],{},[236,1471,244],{},[246,1473,1474,1484,1494],{},[233,1475,1476,1481],{},[251,1477,1478],{},[169,1479,1480],{},"parseInt64(attr)",[251,1482,1483],{},"Parses the string as a 64-bit integer.",[233,1485,1486,1491],{},[251,1487,1488],{},[169,1489,1490],{},"parseFloat64(attr)",[251,1492,1493],{},"Parses the string as a 64-bit float.",[233,1495,1496,1501],{},[251,1497,1498],{},[169,1499,1500],{},"parseDateTime(attr)",[251,1502,1503],{},"Parses the string as a date with time.",[155,1505,1506],{},"A value the function cannot parse becomes zero rather than an error.",[640,1508,1510],{"id":1509},"arrays","Arrays",[227,1512,1513,1521],{},[230,1514,1515],{},[233,1516,1517,1519],{},[236,1518,898],{},[236,1520,244],{},[246,1522,1523],{},[233,1524,1525,1530],{},[251,1526,1527],{},[169,1528,1529],{},"arrayJoin(attr)",[251,1531,1532],{},"Expands an array attribute into one row per element, so you can group by it.",[174,1534,1536],{"className":176,"code":1535,"language":178,"meta":179,"style":179},"group by arrayJoin(db_sql_tables) as table | count()\n",[169,1537,1538],{"__ignoreMap":179},[183,1539,1540,1542,1545,1547,1550,1553,1555],{"class":185,"line":186},[183,1541,190],{"class":189},[183,1543,1544],{"class":196}," arrayJoin(db_sql_tables) ",[183,1546,718],{"class":189},[183,1548,1549],{"class":189}," table",[183,1551,1552],{"class":196}," | ",[183,1554,1449],{"class":678},[183,1556,1557],{"class":196},"()\n",[640,1559,1561],{"id":1560},"time-bucketing","Time bucketing",[155,1563,1564],{},"Each function truncates a time value to the start of its bucket, which makes it useful for grouping over time:",[227,1566,1567,1576],{},[230,1568,1569],{},[233,1570,1571,1573],{},[236,1572,898],{},[236,1574,1575],{},"Rounds down to",[246,1577,1578,1588,1598,1608,1618,1628,1638],{},[233,1579,1580,1585],{},[251,1581,1582],{},[169,1583,1584],{},"toStartOfSecond(_time)",[251,1586,1587],{},"The second.",[233,1589,1590,1595],{},[251,1591,1592],{},[169,1593,1594],{},"toStartOfMinute(_time)",[251,1596,1597],{},"The minute.",[233,1599,1600,1605],{},[251,1601,1602],{},[169,1603,1604],{},"toStartOfFiveMinutes(_time)",[251,1606,1607],{},"The 5-minute interval.",[233,1609,1610,1615],{},[251,1611,1612],{},[169,1613,1614],{},"toStartOfTenMinutes(_time)",[251,1616,1617],{},"The 10-minute interval.",[233,1619,1620,1625],{},[251,1621,1622],{},[169,1623,1624],{},"toStartOfFifteenMinutes(_time)",[251,1626,1627],{},"The 15-minute interval.",[233,1629,1630,1635],{},[251,1631,1632],{},[169,1633,1634],{},"toStartOfHour(_time)",[251,1636,1637],{},"The hour.",[233,1639,1640,1645],{},[251,1641,1642],{},[169,1643,1644],{},"toStartOfDay(_time)",[251,1646,1647],{},"The day.",[174,1649,1651],{"className":176,"code":1650,"language":178,"meta":179,"style":179},"group by toStartOfDay(_time) as day | uniq(enduser_id) as visitors\n",[169,1652,1653],{"__ignoreMap":179},[183,1654,1655,1657,1660,1662,1665,1668,1670],{"class":185,"line":186},[183,1656,190],{"class":189},[183,1658,1659],{"class":196}," toStartOfDay(_time) ",[183,1661,718],{"class":189},[183,1663,1664],{"class":189}," day",[183,1666,1667],{"class":196}," | uniq(enduser_id) ",[183,1669,718],{"class":189},[183,1671,1672],{"class":196}," visitors\n",[212,1674,1676],{"id":1675},"json-functions","JSON functions",[155,1678,1679],{},"When an attribute holds a JSON document, these functions read inside it. Two families are available, and both take the JSON string as the first argument.",[155,1681,1682],{},"The SQL\u002FJSON path functions take one path:",[227,1684,1685,1696],{},[230,1686,1687],{},[233,1688,1689,1691,1694],{},[236,1690,898],{},[236,1692,1693],{},"Returns",[236,1695,244],{},[246,1697,1698,1710,1722],{},[233,1699,1700,1705,1707],{},[251,1701,1702],{},[169,1703,1704],{},"JSON_EXISTS(attr, path)",[251,1706,584],{},[251,1708,1709],{},"Whether the path exists.",[233,1711,1712,1717,1719],{},[251,1713,1714],{},[169,1715,1716],{},"JSON_QUERY(attr, path)",[251,1718,258],{},[251,1720,1721],{},"The value at the path, as JSON.",[233,1723,1724,1729,1731],{},[251,1725,1726],{},[169,1727,1728],{},"JSON_VALUE(attr, path)",[251,1730,258],{},[251,1732,1733],{},"The scalar value at the path.",[155,1735,1736],{},"The ClickHouse functions take one or more path segments:",[227,1738,1739,1749],{},[230,1740,1741],{},[233,1742,1743,1745,1747],{},[236,1744,898],{},[236,1746,1693],{},[236,1748,244],{},[246,1750,1751,1763,1775,1787,1799,1811,1823,1835,1847,1861,1873],{},[233,1752,1753,1758,1760],{},[251,1754,1755],{},[169,1756,1757],{},"JSONHas(attr, path…)",[251,1759,584],{},[251,1761,1762],{},"Whether the member exists.",[233,1764,1765,1770,1772],{},[251,1766,1767],{},[169,1768,1769],{},"JSONLength(attr, path…)",[251,1771,462],{},[251,1773,1774],{},"Number of elements or members.",[233,1776,1777,1782,1784],{},[251,1778,1779],{},[169,1780,1781],{},"JSONType(attr, path…)",[251,1783,258],{},[251,1785,1786],{},"The JSON type of the member.",[233,1788,1789,1794,1796],{},[251,1790,1791],{},[169,1792,1793],{},"JSONExtractString(attr, path…)",[251,1795,258],{},[251,1797,1798],{},"The member as a string.",[233,1800,1801,1806,1808],{},[251,1802,1803],{},[169,1804,1805],{},"JSONExtractInt(attr, path…)",[251,1807,462],{},[251,1809,1810],{},"The member as a signed integer.",[233,1812,1813,1818,1820],{},[251,1814,1815],{},[169,1816,1817],{},"JSONExtractUInt(attr, path…)",[251,1819,462],{},[251,1821,1822],{},"The member as an unsigned integer.",[233,1824,1825,1830,1832],{},[251,1826,1827],{},[169,1828,1829],{},"JSONExtractFloat(attr, path…)",[251,1831,414],{},[251,1833,1834],{},"The member as a float.",[233,1836,1837,1842,1844],{},[251,1838,1839],{},[169,1840,1841],{},"JSONExtractBool(attr, path…)",[251,1843,584],{},[251,1845,1846],{},"The member as a boolean.",[233,1848,1849,1854,1858],{},[251,1850,1851],{},[169,1852,1853],{},"JSONExtractKeys(attr, path…)",[251,1855,1856,258],{},[183,1857],{},[251,1859,1860],{},"The member's keys.",[233,1862,1863,1868,1870],{},[251,1864,1865],{},[169,1866,1867],{},"JSONExtractRaw(attr, path…)",[251,1869,258],{},[251,1871,1872],{},"The member as raw JSON.",[233,1874,1875,1880,1884],{},[251,1876,1877],{},[169,1878,1879],{},"JSONExtractArrayRaw(attr, path…)",[251,1881,1882,258],{},[183,1883],{},[251,1885,1886],{},"The array's elements, each as raw JSON.",[174,1888,1890],{"className":176,"code":1889,"language":178,"meta":179,"style":179},"group by JSONExtractString(http_request_body, 'user', 'plan') as plan | count()\nwhere JSONHas(payload, 'error')\n",[169,1891,1892,1918],{"__ignoreMap":179},[183,1893,1894,1896,1899,1902,1904,1907,1909,1911,1914,1916],{"class":185,"line":186},[183,1895,190],{"class":189},[183,1897,1898],{"class":196}," JSONExtractString(http_request_body, ",[183,1900,1901],{"class":209},"'user'",[183,1903,433],{"class":196},[183,1905,1906],{"class":209},"'plan'",[183,1908,846],{"class":196},[183,1910,718],{"class":189},[183,1912,1913],{"class":196}," plan | ",[183,1915,1449],{"class":678},[183,1917,1557],{"class":196},[183,1919,1920,1922,1925,1928],{"class":185,"line":660},[183,1921,200],{"class":189},[183,1923,1924],{"class":196}," JSONHas(payload, ",[183,1926,1927],{"class":209},"'error'",[183,1929,1162],{"class":196},[212,1931,816],{"id":804},[155,1933,1934,1935,1938],{},"Search is the free-text clause of a query. ",[159,1936,1937],{"href":79},"Searching spans and logs"," documents it in full, with examples. The rules a reference needs:",[1940,1941,1942,1950,1957,1966,1980,1990,2001],"ul",{},[1943,1944,1945,1946,164],"li",{},"Uptrace splits the search string on whitespace into matchers, and ",[1947,1948,1949],"strong",{},"every matcher must match",[1943,1951,1952,1953,1956],{},"One matcher holds pipe-separated alternatives, so ",[169,1954,1955],{},"select|update"," matches either term.",[1943,1958,1959,1960,1963,1964,164],{},"Matching is case-insensitive substring matching, so ",[169,1961,1962],{},"err"," matches ",[169,1965,436],{},[1943,1967,1968,1971,1972,1975,1976,1979],{},[169,1969,1970],{},"-term"," excludes a term, ",[169,1973,1974],{},"attr:value"," scopes the search to one attribute, and ",[169,1977,1978],{},"*:value"," searches the full-text index.",[1943,1981,1982,1983,352,1986,1989],{},"Quote a value with ",[169,1984,1985],{},"\"",[169,1987,1988],{},"'"," to keep spaces and punctuation. A backtick value matches literally, with no escape processing.",[1943,1991,1992,1993,1996,1997,2000],{},"A scope must be a valid OpenTelemetry attribute key, or ",[169,1994,1995],{},"*",". A ",[169,1998,1999],{},"key:"," prefix that is neither is read as part of the word.",[1943,2002,2003,2004,2008],{},"An unscoped search looks at the attributes the query groups by. ",[159,2005,2007],{"href":2006},"\u002Ffeatures\u002Fsearching#search-scope","Search scope"," maps each grouping to the attributes it searches.",[174,2010,2015],{"className":2011,"code":2013,"language":2014},[2012],"language-text","error \"database connection\" -timeout\n*:hello *:error|warning -*:debug\n","text",[169,2016,2013],{"__ignoreMap":179},[479,2018,2020],{"type":2019},"warning",[155,2021,2022,2023,490,2026,2029,2030,2032,2033,2036,2037,2039,2040,2042,2043,164],{},"Regexp search matchers (",[169,2024,2025],{},"~pattern",[169,2027,2028],{},"~scope:pattern",") are not supported, and the parser rejects the ",[169,2031,545],{}," operator with ",[169,2034,2035],{},"regexp matchers are not supported",". To match a pattern, use the ",[169,2038,545],{}," operator of a ",[169,2041,200],{}," filter instead, for example ",[169,2044,2045],{},"where log_message ~ 'group(.*)does not exist'",[212,2047,2049],{"id":2048},"see-also","See also",[1940,2051,2052,2056,2060,2065,2069],{},[1943,2053,2054],{},[159,2055,21],{"href":22},[1943,2057,2058],{},[159,2059,25],{"href":26},[1943,2061,2062],{},[159,2063,2064],{"href":18},"Grouping and systems",[1943,2066,2067],{},[159,2068,1937],{"href":79},[1943,2070,2071],{},[159,2072,2073],{"href":57},"Metrics query language reference",[2075,2076,2077],"style",{},"html pre.shiki code .sD7c4, html code.shiki .sD7c4{--shiki-default:#D73A49}html pre.shiki code .sgsFI, html code.shiki .sgsFI{--shiki-default:#24292E}html pre.shiki code .sYBdl, html code.shiki .sYBdl{--shiki-default:#032F62}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html pre.shiki code .sAwPA, html code.shiki .sAwPA{--shiki-default:#6A737D}html pre.shiki code .sYu0t, html code.shiki .sYu0t{--shiki-default:#005CC5}",{"title":179,"searchDepth":1192,"depth":660,"links":2079},[2080,2081,2085,2086,2090,2097,2098,2099],{"id":214,"depth":660,"text":215},{"id":500,"depth":660,"text":501,"children":2082},[2083,2084],{"id":642,"depth":672,"text":643},{"id":685,"depth":672,"text":686},{"id":724,"depth":660,"text":725},{"id":888,"depth":660,"text":889,"children":2087},[2088,2089],{"id":1136,"depth":672,"text":1137},{"id":1207,"depth":672,"text":1208},{"id":1239,"depth":660,"text":1240,"children":2091},[2092,2093,2094,2095,2096],{"id":1246,"depth":672,"text":1247},{"id":1382,"depth":672,"text":1383},{"id":1460,"depth":672,"text":1461},{"id":1509,"depth":672,"text":1510},{"id":1560,"depth":672,"text":1561},{"id":1675,"depth":660,"text":1676},{"id":804,"depth":660,"text":816},{"id":2048,"depth":660,"text":2049},"Complete reference for the Uptrace span query language: built-in fields, data types, clauses, every aggregate and transform function, the JSON functions, and the search syntax.","md",{"readingTime":2103},{"text":2104,"minutes":2105,"time":2106,"words":2107},"6 min read",5.335,320100,1067,{"title":29},{"title":149,"description":2100},"phPwCm0Q9Q3TpD-GidJfVYLRCwyTvGbdD3vXw5zjQnM",[2112,2114],{"title":25,"path":26,"stem":27,"description":2113,"children":-1},"Query distributed traces by filtering spans, logs, and events across services, and enrich root results with cross-join expressions that aggregate child spans within the same trace.",{"title":15,"path":34,"stem":35,"description":2115,"children":-1},"Browse grouped logs and errors in Uptrace, filter by service or severity, search by text or attribute, and inspect individual records with aggregated stats and per-entry details.",1791361939812]