如何在KQL转换查询中创建空Bag?(不使用parse_json("{}"))
问题:Azure Monitor数据收集规则转换查询中无法创建空Bag
之前在Stack Overflow探讨过KQL创建空Bag的方法,但在Azure Monitor数据收集规则的转换查询里使用dynamic({})会触发语法错误,该方法在Log Analytics查询中却能正常运行(已将转换查询中的source替换为含RawData列的表验证过)。
报错信息
{ "error": { "code": "InvalidPayload", "message": "Data collection rule is invalid", "details": [ { "code": "InvalidTransformQuery", "target": "properties.dataFlows[0]", "message": "Error occurred while compiling query in query: SyntaxError:0x00000001 at 7:118 : extraneous input 'dynamic' expecting {'(', '*', '[', '+', '-', 'access', 'accounts', 'add', 'admin', 'admins', 'alias', 'all', 'alter', 'alter-merge', 'append', 'async', 'attach', 'basicauth', 'bin', 'cache', 'caching', 'capacity', 'case', 'categorize', 'cluster', 'column', 'columns', 'columnifexists', 'commands', 'commpools', 'completed', 'compressed', 'count', 'crash', 'create', 'createdon', 'csl', 'cslschema', 'csv', 'data', 'database', 'databasecreators', 'databases', 'datatable', 'declare', 'decryption-certificate-thumbprint', 'define', 'delete', 'detach', 'details', 'diagnostics', 'disable', 'docstring', 'drop', 'drop-pretend', 'dup-next-failed-ingest', 'dup-next-ingest', 'echo', 'effective', 'enable', 'encoding', 'entity', 'ephemeral', 'evaluate', 'except', 'execute', 'export', 'extend', 'extent', 'extentcontainers', 'extents', 'extentsmerge', 'fabric', 'fabriccache', 'fabricclocks', 'fabriclocks', 'facet', 'failures', 'filter', 'folder', 'force', 'fork', 'freshness', 'from', 'function', 'functions', 'groups', 'hash', 'hot', 'hotdata', 'hotindex', 'hours', 'id', 'if_later_than', 'ifexists', 'iff', 'ifnotexists', 'iif', 'ingest', 'ingestion', 'ingestions', 'ingestiontime', 'inline', 'into', 'join', 'json', 'keys', 'let', 'limit', 'load', 'local', 'mapping', 'mappings', 'memory', 'merge', 'metadata', 'monitoring', 'move', 'mvexpand', 'nan', 'none', 'not', 'null', 'nulls', 'on', 'older', 'operations', 'order', 'pack', 'parse', 'password', 'pattern', 'persist', 'plugin', 'plugins', 'policies', 'policy', 'pretend', 'prettyname', 'principal', 'principals', 'print', 'project', 'project-away', 'project-rename', 'purge', 'query', 'query_parameters', 'queryexecution', 'queryplan', 'querythrottling', 'quick', 'range', 'readonly', 'readwrite', 'rebalance', 'rebalance-pretend', 'rebuild', 'recycle', 'reduce', 'rename', 'render', 'replace', 'reset', 'restrict', 'retention', 'roles', 'roworder', 'roworderpolicy', 'running', 'save', 'schema', 'script', 'set-or-append', 'set-or-replace', 'show', 'sort', 'state', 'step', 'stream', 'summarize', 'storage', 'table', 'tables', 'tags', 'take', 'tempstorage', 'threshold', 'throw', 'toscalar', 'totable', 'trace', 'traceresults', 'tsv', 'type', 'typeof', 'undo', 'union', 'update', 'user', 'users', 'uuid', 'version', 'view', 'volatile', 'warm', 'warming', 'whatif', 'where', 'with', 'bool', 'guid', LONGLITERAL, INTLITERAL, REALLITERAL, STRINGLITERALX, BOOLEANLITERAL, DATETIMELITERAL, TIMESPANLITERAL, TYPELITERAL, GUIDLITERAL, IDENTIFIER}\r\nSyntaxError:0x00000004 at 7:126 : no viable alternative at input '({'\r\nSyntaxError:0x00000003 at 7:130 : mismatched input ')' expecting <EOF>" } ] } }
报错指向代码行
| extend Context = todynamic(iif(ContextStr startswith_cs "{" and ContextStr endswith_cs "}", parse_json(ContextStr), dynamic({})))
需求
需找到**不使用parse_json("{}")**的替代方案,在Azure Monitor数据收集规则的转换查询中创建空Bag。
解决方案
提供以下几种兼容转换查询的替代方法:
- 使用
pack()函数创建空Bagpack()函数不传入任何键值对时会返回空Bag,该写法在转换查询中支持:
| extend Context = iif(ContextStr startswith_cs "{" and ContextStr endswith_cs "}", parse_json(ContextStr), pack())
- 结合
toscalar()包装空动态值
若pack()仍有问题,可尝试用toscalar()绕过语法检查:
| extend Context = iif(ContextStr startswith_cs "{" and ContextStr endswith_cs "}", parse_json(ContextStr), toscalar(dynamic({})))
- 预先定义空Bag变量
通过let语句提前定义空Bag,再在逻辑中引用:
let empty_bag = pack(); source | extend Context = iif(ContextStr startswith_cs "{" and ContextStr endswith_cs "}", parse_json(ContextStr), empty_bag)
内容的提问来源于stack exchange,提问作者Simao Gomes Viana
相关产品推荐
相关产品推荐

