histogram

This page explains how to use the histogram aggregation function in APL.

The histogram aggregation in APL allows you to create a histogram that groups numeric values into intervals or “bins.” This is useful for visualizing the distribution of data, such as the frequency of response times, request durations, or other continuous numerical fields. You can use it to analyze patterns and trends in datasets like logs, traces, or metrics. It’s especially helpful when you need to summarize a large volume of data into a digestible form, providing insights on the distribution of values.

The histogram aggregation is ideal for identifying peaks, valleys, and outliers in your data. For example, you can analyze the distribution of request durations in web server logs or span durations in OpenTelemetry traces to understand performance bottlenecks.

Usage

Syntax

histogram(numeric_field, number_of_bins)

Parameters

  • numeric_field: The numeric field to create a histogram for. For example, request duration or span duration.
  • number_of_bins: The number of bins (intervals) to use for grouping the numeric values.

Returns

The histogram aggregation returns a table where each row represents a bin, along with the number of occurrences (counts) that fall within each bin.

Use case examples

You can use the histogram aggregation to analyze the distribution of request durations in web server logs.

Query

['sample-http-logs']
| summarize histogram(req_duration_ms, 100) by bin_auto(_time)

Run in Playground

Output

req_duration_ms_bincount
050
100200
200120

This query creates a histogram that groups request durations into bins of 100 milliseconds and shows the count of requests in each bin. It helps you visualize how frequently requests fall within certain duration ranges.

In OpenTelemetry traces, you can use the histogram aggregation to analyze the distribution of span durations.

Query

['otel-demo-traces']
| summarize histogram(duration, 100) by bin_auto(_time)

Run in Playground

Output

duration_bincount
0.1s30
0.2s120
0.3s50

This query groups the span durations into 100ms intervals, making it easier to spot latency issues in your traces.

In security logs, the histogram aggregation helps you understand the frequency distribution of request durations to detect anomalies or attacks.

Query

['sample-http-logs']
| where status == '200'
| summarize histogram(req_duration_ms, 50) by bin_auto(_time)

Run in Playground

Output

req_duration_ms_bincount
0150
50400
100100

This query analyzes the request durations for HTTP 200 (Success) responses, helping you identify patterns in security-related events.

  • percentile: Use percentile when you need to find the specific value below which a percentage of observations fall, which can provide more precise distribution analysis.
  • avg: Use avg for calculating the average value of a numeric field, useful when you are more interested in the central tendency rather than distribution.
  • sum: The sum function adds up the total values in a numeric field, helpful for determining overall totals.
  • count: Use count when you need a simple tally of rows or events, often in conjunction with histogram for more basic summarization.

Other query languages