ContentsThe library

Counting Things as They Arrive

Three Shapes, and the Question Tells You Which One

Last timeTwo Different Clocks

A window is a decision about which events belong together. There are three shapes in common use, the question being asked picks one, and each one costs a different amount of memory.

The three shapes

Since no aggregate is possible over an input with no end, every streaming

aggregate is over a window, and a window is a rule saying which events belong

together. Three rules cover almost everything built in practice.

A fixed window, also called tumbling, cuts time into adjacent equal pieces. Nine

to ten, ten to eleven, eleven to twelve. The pieces do not overlap and they

leave no gaps, so each event belongs to exactly one of them. This is the shape

everybody draws first and the shape most reports are written against.

A sliding window has a width and an advance, and the width is larger than the

advance. A one-hour window advancing every five minutes gives you a window

starting at 9:00, another at 9:05, another at 9:10, each one an hour long. They

overlap heavily, which means a single event belongs to twelve of them at once.

A session window has no boundaries until the data supplies them. You specify a

gap, say thirty minutes. A window opens on the first event for a key, extends

with each new event, and closes when the gap passes with nothing arriving. Two

sessions for the same key can be four minutes long and nine hours long, and

neither has anything to do with the clock on the wall.

FIG 1One event, and which windows contain it
fixed, nine to quarter past: contains itfixed, quarter past to half: does notsliding, fifteen wide advancing five: also contains it102030405014the event0nine60tenminutes past nine, with an event at minute 14
Three of the four windows drawn here cover minute 14 under some scheme, and the event is a member of each of those. Under the fixed scheme it belongs to one window and the accounting is simple. Under the sliding scheme shown, with a fifteen-minute width advancing every five minutes, it belongs to three of them at once, and every aggregate it contributes to has to be updated when it arrives.

Reading the shape off the question

The shape is not a preference. It is determined by the question, and the words

of the question usually give it away.

Per hour, per day, per calendar month means fixed. The question is about a

named period that somebody else defined, usually for reporting or billing, and

the periods must tile without overlap so that the parts add to the whole.

In the last hour, asked repeatedly, means sliding. The question is about a

quantity that should be current rather than about a named period. Alerting is

the clearest case. Nobody wants to know the error rate for the 10:00 hour at

11:00; they want to know the error rate over the last five minutes, now, and

again thirty seconds from now. A fixed window used here produces an alert that

is on average half a window out of date and resets its count at a boundary for

no reason connected to anything real.

Per visit, per conversation, per trip, per editing burst means session. The

question is about an episode of activity whose length is a property of the

behaviour rather than of the clock.

FIG 2Which shape each question wants
fixedslidingsession
sales in each calendar d100
invoice totals per month100
error rate right now010
is traffic unusual this 010
pages read per visit001
length of a support conv001
distance of one delivery001
The two marked rows are the ones most often done with the wrong shape. An alerting metric on a fixed window is stale for most of each window and resets at an arbitrary boundary. A per-visit metric on a fixed window splits any visit crossing the boundary into two shorter visits, which drags the average down and makes the figure depend on when people happen to arrive rather than on what they did.

The session mistake deserves a sentence of its own, because it is silent. If

visits are measured in fixed hourly windows, a visit from 10:50 to 11:10 is

recorded as two visits of ten minutes each. Nothing errors, the number is

plausible, and the reported average visit length is wrong in a direction that

depends on your window size.

The lesson stops here

4 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Sort This. There Is No Last Row.
  2. 02The Spike at Nine Was Six Hours of Traffic Arriving at Onceopening only
  3. 03Three Shapes, and the Question Tells You Which Oneyou are here
  4. 04Nothing Can Tell You That Nothing Else Is Comingopening only
  5. 05Somebody Has Already Seen the Number You Are About to Changeopening only
  6. 06An Average Needs Two Numbers, a Median Needs All of Themopening only
  7. 07Twelve Kilobytes Will Count a Billion Different Thingsopening only
  8. 08The Windows Came Back, and So Did Nine Minutes of Totalsopening only

Read alongside