elastic / elastic/apm

Cardinality for Elasticsearch span names is too high

Open
#439 4 comments 0 reactions 0 assignees View on GitHub
apm-agents
Dominant language
Gherkin
Stars
427
Forks
125
PR merge metrics
No merged PRs in 30d

Description

Currently, the span name is `Elasticsearch: ${http.method} ${http.url.path}`. The issue is that the path can contain document IDs, such as `GET /customers/_doc/42`.

This is problematic if we want to roll up metrics based on `span.name`.

Agents may only have the access to the HTTP request info that the low-level RestClients expose.

An idea that needs further validation is to remove any path segments that come after a path segment that begins with an underscore. Examples:
* `GET /customers/_doc/42` -> `GET /customers/_doc`
* `GET /_cluster/health/my-index-000001` -> `GET /_cluster`
* `GET /_alias/my-alias` -> `GET /_alias`

While this strategy might sometimes result in what feels like too low cardinality (`GET /_cluster/health/my-index-000001` or `GET /_cluster/health` is not problematic), it's an easy strategy that should work quite generically.

As this would chop off some parts of the URL, it becomes important for agents to collect the full URL in `context.http.url`. This overlaps with https://github.com/elastic/apm-agent-nodejs/issues/2019

While at it, we should also consider dropping the `Elasticsearch: ` prefix as suggested here: https://github.com/elastic/apm/pull/420#issuecomment-828279997

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.