You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Azure Resource Graph Explorer查询指定子网的关联资源

如何查询Azure中关联指定子网的所有资源

问题原因

你的原查询仅筛选了microsoft.network/networkinterfaces类型资源,但配置了出站虚拟网络集成的Azure Web App不会通过网络接口(NIC)关联子网,而是直接在Web App资源的properties.virtualNetworkSubnetId字段中存储子网ID,因此原查询无法找到这类资源。此外,仅查NIC也会遗漏其他关联子网的资源(如负载均衡器、应用网关等)。

解决方案

1. 先获取目标子网的完整ID(精准匹配)

先运行以下查询获取snet-dev子网的完整资源ID,避免模糊匹配导致的错误:

Resources
| where type =~ "microsoft.network/virtualnetworks/subnets"
| where name =~ "snet-dev"
| project SubnetId = id, SubnetName = name, ResourceGroup = resourceGroup

2. 查询所有关联该子网的资源

使用下面的Kusto查询,涵盖Web App、虚拟机/VMSS(通过NIC)、负载均衡器、应用网关等常见关联子网的资源类型:

// 定义目标子网的完整ID(替换为上面查询得到的ID,或保留自动查询逻辑)
let targetSubnetId = toscalar(
    Resources
    | where type =~ "microsoft.network/virtualnetworks/subnets"
    | where name =~ "snet-dev"
    | project id
);
// 筛选所有关联目标子网的资源
Resources
| where 
    // Web App/函数应用 出站虚拟网络集成
    (type =~ "microsoft.web/sites" && properties.virtualNetworkSubnetId == targetSubnetId)
    or
    // 网络接口关联的子网(覆盖VM、VMSS等资源)
    (type =~ "microsoft.network/networkinterfaces" && array_length(properties.ipConfigurations) > 0 && any(properties.ipConfigurations, ipConfig => ipConfig.properties.subnet.id == targetSubnetId))
    or
    // 负载均衡器后端池关联子网
    (type =~ "microsoft.network/loadbalancers" && array_length(properties.backendAddressPools) > 0 && any(properties.backendAddressPools, pool => pool.properties.subnet.id == targetSubnetId))
    or
    // 应用网关关联子网
    (type =~ "microsoft.network/applicationgateways" && properties.gatewayIPConfigurations[0].properties.subnet.id == targetSubnetId)
| project 
    ResourceId = id,
    ResourceName = name,
    ResourceType = type,
    ResourceGroup = resourceGroup,
    Location = location,
    AssociatedSubnet = case(
        type =~ "microsoft.web/sites", properties.virtualNetworkSubnetId,
        type =~ "microsoft.network/networkinterfaces", strcat_array(array_map(properties.ipConfigurations, ipConfig => ipConfig.properties.subnet.id), ", "),
        type =~ "microsoft.network/loadbalancers", strcat_array(array_map(properties.backendAddressPools, pool => pool.properties.subnet.id), ", "),
        type =~ "microsoft.network/applicationgateways", properties.gatewayIPConfigurations[0].properties.subnet.id,
        ""
    )

3. 扩展其他资源类型(可选)

如果需要覆盖更多资源类型(如Azure Kubernetes Service的节点子网、Azure Bastion子网等),可以在where条件中添加对应的类型和子网字段判断,例如:

or
// AKS 节点池关联子网
(type =~ "microsoft.containerservice/managedclusters" && array_length(properties.agentPoolProfiles) > 0 && any(properties.agentPoolProfiles, pool => pool.vnetSubnetID == targetSubnetId))

关键说明

  • 使用toscalar自动获取子网ID,避免手动输入错误;如果环境中有多个同名子网,建议在子网查询中添加resourceGroup筛选来精准定位。
  • any()函数用于处理资源存在多个IP配置/后端池的情况,确保匹配所有关联目标子网的实例。
  • strcat_array用于将多个关联子网ID拼接成字符串,便于查看。

内容的提问来源于stack exchange,提问作者fascynacja

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 04:57:21