You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

KQL如何排除首尾不完整分箱?如何用移动平均替代分箱统计?

KQL分箱首尾不完整问题优化及移动平均改造方案

一、优化首尾分箱不完整的更优方法

1. 精确对齐分箱时间边界

通过对齐到周起始/结束时间,确保所有分箱都是完整的7天周期:

let start_time = startofweek(ago(90d));  // 将起始时间对齐到90天前的周开始
let end_time = startofweek(now());       // 将结束时间对齐到当前周开始,排除不完整的当前周
AppRequests
| where AppRoleName contains '-apim'
| where TimeGenerated between (start_time .. end_time)
| summarize count() by bin(TimeGenerated, 7d)
| render timechart

2. 用make-series补全空分箱并过滤不完整周期

make-series会自动补全无数据的分箱,再通过计算分箱实际时长过滤不完整的周期:

AppRequests
| where AppRoleName contains '-apim'
| where TimeGenerated > ago(90d)
| make-series request_count = count() on TimeGenerated from ago(90d) to now() step 7d
| mv-expand TimeGenerated, request_count
| extend bin_actual_days = datetime_diff('day', next(TimeGenerated, 1), TimeGenerated)
| where bin_actual_days == 7  // 仅保留完整7天的分箱
| project TimeGenerated, request_count
| render timechart

3. 动态计算过滤规则

避免硬编码天数,根据分箱大小动态排除首尾不完整的分箱:

let bin_size = 7d;
AppRequests
| where AppRoleName contains '-apim'
| where TimeGenerated > ago(90d)
| summarize count() by bin(TimeGenerated, bin_size)
| where TimeGenerated >= startofweek(ago(90d)) 
  and TimeGenerated <= now() - bin_size  // 自动排除最后一个不完整分箱
| render timechart

二、改为移动平均统计的实现方式

方法1:make-series + series_moving_avg

先按天聚合数据,再计算7天滚动平均:

AppRequests
| where AppRoleName contains '-apim'
| where TimeGenerated > ago(90d)
| make-series daily_count = count() on TimeGenerated from ago(90d) to now() step 1d
| extend weekly_moving_avg = series_moving_avg(daily_count, 7, true)  // true表示窗口中心对齐
| mv-expand TimeGenerated, weekly_moving_avg
| project TimeGenerated, weekly_moving_avg
| render timechart

方法2:使用rolling函数(Kusto新版本支持)

基于日聚合结果直接计算7天滚动平均:

AppRequests
| where AppRoleName contains '-apim'
| where TimeGenerated > ago(90d)
| summarize daily_count = count() by bin(TimeGenerated, 1d)
| rolling avg(daily_count) over (TimeGenerated between 6d ago and now)  // 滚动窗口覆盖7天
| project TimeGenerated, weekly_moving_avg = avg_daily_count
| render timechart

内容的提问来源于stack exchange,提问作者Edwin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 21:42:05