Moving Average Query

These Aggregate Window Functions consume standard Druid Aggregators and outputs additional windowed aggregates called Averagers.

High level algorithm

Moving Average encapsulates the groupBy query (Or in case of no dimensions) in order to rely on the maturity of these query types.

It runs the query in two main phases:

  1. Runs an inner groupBy or query to compute Aggregators (i.e. daily count of events).
  2. Passes over aggregated results in Broker, in order to compute Averagers (i.e. moving 7 day average of the daily count).

Main enhancements provided by this extension:

  1. Functionality: Extending druid query functionality (i.e. initial introduction of Window Functions).
  2. Performance: Improving performance of such moving aggregations by eliminating multiple segment scans.

Further reading

Moving Average

Analytic Functions

Operations

Use tool shipped with Druid to install this extension on all Druid broker and router nodes.

Enabling

After installation, to enable this extension, just add to druid.extensions.loadList in broker and routers’ runtime.properties file and then restart broker and router nodes.

  1. druid.extensions.loadList=["druid-moving-average-query"]

There are currently no configuration properties specific to Moving Average.

Limitations

  • movingAverage is missing support for the following groupBy properties: subtotalsSpec, virtualColumns.
  • movingAverage is missing support for the following timeseries properties: descending.
  • movingAverage is missing support for SQL-compatible null handling (So setting druid.generic.useDefaultValueForNull in configuration will give an error).
  • Most properties in the query spec derived from groupBy query / , see documentation for these query types.

Averagers

Averagers are used to define the Moving-Average function. Averagers are not limited to an average - they can also provide other types of window functions such as MAX()/MIN().

These are properties which are common to all Averagers:

propertydescriptionrequired?
typeAverager type; See Averager typesyes
nameAverager nameyes
fieldNameInput name (An aggregation name)yes
bucketsNumber of lookback buckets (time periods), including current one. Must be >0yes
cycleSizeCycle size; Used to calculate day-of-week option; See no, defaults to 1

Averager types:

  • :
    • doubleMean
    • doubleMeanNoNulls
    • doubleSum
    • doubleMax
    • doubleMin
    • longMean
    • longMeanNoNulls
    • longSum
    • longMax
    • longMin

Standard averagers

These averagers offer four functions:

  • Mean (Average)
  • MeanNoNulls (Ignores empty buckets).
  • Sum
  • Max
  • Min

Ignoring nulls: Using a MeanNoNulls averager is useful when the interval starts at the dataset beginning time. In that case, the first records will ignore missing buckets and average won’t be artificially low. However, this also means that empty days in a sparse dataset will also be ignored.

Example of usage:

This optional parameter is used to calculate over a single bucket within each cycle instead of all buckets. A prime example would be weekly buckets, resulting in a Day of Week calculation. (Other examples: Month of year, Hour of day).

I.e. when using these parameters:

  • granularity: period=P1D (daily)
  • buckets: 28
  • cycleSize: 7

All examples are based on the Wikipedia dataset provided in the Druid .

Basic example

Calculating a 7-buckets moving average for Wikipedia edit deltas.

Query syntax:

  1. "queryType": "movingAverage",
  2. "dataSource": "wikipedia",
  3. "granularity": {
  4. "type": "period",
  5. "period": "PT30M"
  6. },
  7. "intervals": [
  8. "2015-09-12T00:00:00Z/2015-09-13T00:00:00Z"
  9. ],
  10. "aggregations": [
  11. {
  12. "name": "delta30Min",
  13. "fieldName": "delta",
  14. "type": "longSum"
  15. }
  16. ],
  17. "averagers": [
  18. {
  19. "name": "trailing30MinChanges",
  20. "fieldName": "delta30Min",
  21. "type": "longMean",
  22. "buckets": 7
  23. }
  24. ]
  25. }

Result:

Calculating a 7-buckets moving average for Wikipedia edit deltas, plus a ratio between the current period and the moving average.

Query syntax:

  1. {
  2. "dataSource": "wikipedia",
  3. "granularity": {
  4. "type": "period",
  5. "period": "PT30M"
  6. },
  7. "intervals": [
  8. "2015-09-12T22:00:00Z/2015-09-13T00:00:00Z"
  9. ],
  10. "aggregations": [
  11. {
  12. "name": "delta30Min",
  13. "fieldName": "delta",
  14. "type": "longSum"
  15. }
  16. ],
  17. "averagers": [
  18. {
  19. "name": "trailing30MinChanges",
  20. "fieldName": "delta30Min",
  21. "type": "longMean",
  22. }
  23. ],
  24. "postAveragers" : [
  25. {
  26. "name": "ratioTrailing30MinChanges",
  27. "type": "arithmetic",
  28. "fn": "/",
  29. "fields": [
  30. {
  31. "type": "fieldAccess",
  32. "fieldName": "delta30Min"
  33. },
  34. "type": "fieldAccess",
  35. "fieldName": "trailing30MinChanges"
  36. }
  37. ]
  38. }
  39. ]
  40. }

Result:

Cycle size example

Calculating an average of every first 10-minutes of the last 3 hours:

  1. {
  2. "queryType": "movingAverage",
  3. "dataSource": "wikipedia",
  4. "granularity": {
  5. "type": "period",
  6. "period": "PT10M"
  7. },
  8. "intervals": [
  9. "2015-09-12T00:00:00Z/2015-09-13T00:00:00Z"
  10. ],
  11. "aggregations": [
  12. {
  13. "name": "delta10Min",
  14. "fieldName": "delta",
  15. "type": "doubleSum"
  16. }
  17. ],
  18. "averagers": [
  19. {
  20. "name": "trailing10MinPerHourChanges",
  21. "fieldName": "delta10Min",
  22. "type": "doubleMeanNoNulls",
  23. "buckets": 18,
  24. "cycleSize": 6
  25. }
  26. ]