ES|QL TO_COUNTER function
Converts a numeric value to its counter type equivalent.
field-
Input value. The input can be a single- or multi-valued column or an expression.
Converts a numeric value to its counter equivalent. The output type is determined by the input: long converts to counter_long, integer to counter_integer, and double to counter_double. No values are modified; only the type annotation changes. If the input is already a counter, the function is a no-op. This is useful when a metric field was misclassified as a plain numeric type instead of a counter in the index mapping. This function is also available as the ::counter cast operator.
| field | result |
|---|---|
| counter_double | counter_double |
| counter_integer | counter_integer |
| counter_long | counter_long |
| double | counter_double |
| integer | counter_integer |
| long | counter_long |
TS k8s
| STATS rate_bytes_in=avg(rate(network.total_bytes_in::counter)) BY time_bucket = bucket(@timestamp,1minute)
| EVAL rate_bytes_in=ROUND(rate_bytes_in, 6) | KEEP rate_bytes_in, time_bucket
| SORT rate_bytes_in DESC, time_bucket DESC | LIMIT 10;
| rate_bytes_in:double | time_bucket:datetime |
|---|---|
| 19.281831 | 2024-05-10T00:19:00.000Z |
| 18.232182 | 2024-05-10T00:20:00.000Z |
| 14.771992 | 2024-05-10T00:17:00.000Z |
| 14.757574 | 2024-05-10T00:07:00.000Z |
| 13.925902 | 2024-05-10T00:01:00.000Z |
| 13.037712 | 2024-05-10T00:18:00.000Z |
| 12.610458 | 2024-05-10T00:04:00.000Z |
| 10.808185 | 2024-05-10T00:14:00.000Z |
| 10.410099 | 2024-05-10T00:16:00.000Z |
| 9.406699 | 2024-05-10T00:09:00.000Z |
| ; |
Applying TO_COUNTER to a field that is a genuine gauge, rather than a misclassified counter, will produce raw gauge values with counter semantics. Results from aggregations on such values are not meaningful.