如何修改KQL查询以绘制Azure Function调用失败数完整时间折线图?
解决Azure Function失败调用数折线图显示0值的问题
要让折线图展示包含0在内的所有时间段失败数,你需要先生成覆盖查询时间范围的完整时间序列,再和失败统计结果做左连接补全0值。修改后的KQL查询如下:
// 1. 生成覆盖整个查询时间范围的5秒间隔时间序列 let time_range = range timestamp from ago(1h) to now() step 5s; // 时间范围可按需调整,比如改为ago(24h) // 2. 统计指定函数的失败调用数,按5秒分组 let failed_counts = requests | where cloud_RoleName =~ '************' and operation_Name =~ '************' | where success <> "True" | summarize failed_count = count() by bin(timestamp, 5s); // 3. 左连接时间序列和统计结果,补全0值 time_range | left join failed_counts on timestamp | project timestamp, failed_count = coalesce(failed_count, 0) | render timechart
关键修改说明:
- 生成完整时间序列:用
range函数创建查询时间范围内所有5秒的时间区间,确保每个时间段都被包含,不管有没有失败。 - 分离统计逻辑:先过滤并统计失败调用,再和时间序列关联,避免提前过滤掉无失败的时间段。
- 补全0值:用
coalesce函数把左连接后缺失的failed_count值替换为0,保证每个时间点都有数值。
如果想自动适配目标函数的实际时间范围,不用手动调整时间区间,可改用以下动态获取时间范围的版本:
let min_time = toscalar(requests | where cloud_RoleName =~ '************' and operation_Name =~ '************' | summarize min(timestamp)); let max_time = toscalar(requests | where cloud_RoleName =~ '************' and operation_Name =~ '************' | summarize max(timestamp)); let time_range = range timestamp from min_time to max_time step 5s; let failed_counts = requests | where cloud_RoleName =~ '************' and operation_Name =~ '************' | where success <> "True" | summarize failed_count = count() by bin(timestamp, 5s); time_range | left join failed_counts on timestamp | project timestamp, failed_count = coalesce(failed_count, 0) | render timechart
内容的提问来源于stack exchange,提问作者Bhav
相关产品推荐
相关产品推荐

