Schedule icon
If icon
Write icon
FluxQuery icon
IonToCsv icon
Query icon
Loop icon
Switch icon
SlackIncomingWebhook icon
Log icon

Detect metric anomalies in InfluxDB with DuckDB and Slack

Detect InfluxDB time-series metric anomalies with DuckDB Z-score profiling and route multi-tier alerts to Slack.

Categories
DataInfrastructure

Diagram unavailable

We could not build the topology for this blueprint. The flow itself is valid, use the YAML on the left to run it.

Automate time-series metric anomaly detection by querying InfluxDB CPU usage points, calculating statistical Z-score baseline deviations using DuckDB, and routing severity notifications to Slack.

Prerequisites

  • InfluxDB v2 instance reachable from Kestra.
  • Slack Incoming Webhook URL.

Secrets

  • INFLUXDB_TOKEN: API token with read/write access.
  • SLACK_WEBHOOK_URL: Slack Incoming Webhook URL.

Set environment secrets in open-source Kestra:

export SECRET_INFLUXDB_TOKEN=$(echo -n "<your-token>" | base64)
export SECRET_SLACK_WEBHOOK_URL=$(echo -n "<your-webhook>" | base64)

InfluxDB Setup

Run InfluxDB in Docker:

docker run -d --name influxdb -p 8086:8086 -e DOCKER_INFLUXDB_INIT_MODE=setup -e DOCKER_INFLUXDB_INIT_USERNAME=admin -e DOCKER_INFLUXDB_INIT_PASSWORD=<choose-a-password> -e DOCKER_INFLUXDB_INIT_ORG=my-org -e DOCKER_INFLUXDB_INIT_BUCKET=metrics -e DOCKER_INFLUXDB_INIT_ADMIN_TOKEN=<choose-a-token> influxdb:2.7
docker network connect kestra_default influxdb

Quick Start

  1. Define environment secrets.
  2. Import workflow into Kestra and execute with seed_demo_data: true.

Inputs

  • influxdb_url (STRING, default http://influxdb:8086): InfluxDB base URL.
  • influxdb_org (STRING, default my-org): InfluxDB organization.
  • influxdb_bucket (STRING, default metrics): bucket holding the metrics.
  • seed_demo_data (BOOLEAN, default true): writes demo host metrics before detection. Scheduled runs set it to false.
  • lookback (SELECT: 1h, 6h, 24h, default 1h): query time window.
  • warning_z (SELECT: 2.0, 2.5, 3.0, default 2.0): minimum z-score for a WARNING.
  • critical_z (SELECT: 3.5, 4.0, 5.0, default 3.5): minimum z-score for a CRITICAL.

Outputs

  • {{ outputs.query_metrics.uri }}: Ion file returned by the Flux query.
  • {{ outputs.ion_to_csv.uri }}: CSV file passed to DuckDB.
  • {{ outputs.detect_anomalies.rows }} and {{ outputs.detect_anomalies.size }}: flagged hosts and their count.

Links

Pitfalls

  • Baseline query partitions rows by host ordered by _time DESC and excludes the latest point (rn > 1).
  • Standard deviation of 0 is guarded by NULLIF(b.stddev_val, 0).
  • Seed timestamps use {{ now() | dateAdd(-N, 'MINUTES') | timestampNano }} (19 digits) to prevent line protocol duplicate overwrites.
See How

New to Kestra?

Use blueprints to kickstart your first workflows.