KQL Join操作仅返回左表列的问题咨询
问题分析与解决
你的查询里有个关键错误:在定义完table1后写了table1;,这会让KQL直接返回table1的结果,后面定义table2和执行join的代码根本没机会运行,所以你看到的只是table1的列,自然看不到table2的内容。
另外,就算去掉这句,join后如果有重复列名(比如两个表都有itemCount),KQL会自动给重复列加后缀(比如itemCount1),你可以通过project明确指定要保留的列,避免结果混乱。
修正后的查询代码
let table1 = view() { let table3 = view() {requests | project name, itemCount | where name == "ProcessApplicationLogs" }; let table4 = view() {exceptions | project operation_Name, itemCount | where operation_Name == "ProcessApplicationLogs" }; table3 | join kind=leftouter table4 on $left.name == $right.operation_Name | summarize TotalExceptions = count() by tostring(name), tostring(itemCount) }; // 移除多余的table1; 让后续代码正常执行 let table2 = view() { let table5 = view() {requests | project name, itemCount | where name == "ProcessApplicationLogs" }; let table6 = view() {exceptions | project operation_Name, itemCount | where operation_Name == "ProcessApplicationLogs" }; table5 | join kind=leftouter table6 on $left.name == $right.operation_Name | summarize TotalExceptions = count() by tostring(operation_Name), tostring(itemCount) }; // 执行join后,用project重命名重复列,明确展示两个表的内容 table2 | join kind=leftouter table1 on $left.operation_Name == $right.name | project table2_operationName = operation_Name, table2_itemCount = itemCount, table2_totalExceptions = TotalExceptions, table1_name = name, table1_itemCount = itemCount1, table1_totalExceptions = TotalExceptions1
关键修改点
- 移除
table1定义后的table1;语句,确保后续的table2定义和join操作能正常执行。 - 通过
project重命名重复列,把两个表的字段分开标注,避免结果混淆,同时明确展示两边的列数据。
内容的提问来源于stack exchange,提问作者vpn
相关产品推荐
相关产品推荐

