如何在Log Analytics创建集成仪表板并编写事务追踪聚合查询?
Log Analytics集成仪表板查询思路(基于给定日志结构)
一、核心结果聚合查询
用于生成仪表板总览类指标,展示整体事务处理情况
- 按环境+组件+数据类型统计事务成功率
YourLogTable | extend Environment = tostring(einviornment), Component = tostring(sourceComponent), DataCategory = tostring(componentProperties.data) | summarize TotalTransactions = count(), SuccessCount = countif(success == true), FailureCount = countif(success == false), SuccessRate = round(SuccessCount * 100.0 / TotalTransactions, 2) by Environment, Component, DataCategory | sort by Environment, Component
该查询可生成各环境下不同组件处理各类数据的核心指标,适合用卡片、柱状图展示,快速定位低成功率的组件或数据类型。
- 按时间维度的事务趋势统计
YourLogTable | extend Environment = tostring(einviornment), SuccessStatus = iif(success == true, "成功", "失败") | summarize TransactionCount = count() by bin(TimeGenerated, 1h), Environment, SuccessStatus | sort by TimeGenerated asc
按小时粒度统计不同环境的成功/失败事务量变化,用折线图展示可直观观察流量波动、异常峰值时段。
二、组件维度事务跟踪查询
聚焦单个组件的处理细节,定位子组件或特定业务场景的问题
- 单个主组件下子组件事务统计
YourLogTable | where sourceComponent == "目标组件名称" | extend SubComponent = tostring(subSourceComponent), Environment = tostring(einviornment) | summarize Total = count(), Failures = countif(success == false) by Environment, SubComponent | sort by Failures desc
查看指定主组件下各子工作流的处理表现,快速定位出错率高的子组件。
- 组件失败事务的业务字段关联
YourLogTable | extend Component = tostring(sourceComponent), DebtorID = tostring(businessKeys.debtorID), TargetSystem = tostring(componentProperties.target) | where success == false | project TimeGenerated, Component, DebtorID, TargetSystem, errorMessage | sort by TimeGenerated desc
筛选组件的失败事务并关联业务关键字段(如debtorID),便于直接定位受影响的业务数据。
三、全链路事务跟踪查询
利用correlationID实现跨组件的事务流转追踪
- 单个事务的全链路详情
YourLogTable | where correlationID == "指定关联ID" | extend Component = tostring(sourceComponent), SubComponent = tostring(subSourceComponent), SourceSystem = tostring(componentProperties.source), TargetSystem = tostring(componentProperties.target), Status = iif(success == true, "成功", "失败") | project TimeGenerated, Status, Component, SubComponent, SourceSystem, TargetSystem, executionID, errorMessage | sort by TimeGenerated asc
输入具体的correlationID,还原该事务在各个组件间的完整流转路径、每个节点的状态及错误信息。
- 异常链路批量排查
YourLogTable | where success == false | extend CorrelationID = tostring(correlationID) | join kind=inner ( YourLogTable | extend CorrelationID = tostring(correlationID) | summarize ComponentFlow = make_set(sourceComponent) by CorrelationID ) on CorrelationID | project TimeGenerated, CorrelationID, ComponentFlow, errorMessage, businessKeys.debtorID | sort by TimeGenerated desc
批量找出所有失败事务的跨组件流转路径,快速定位涉及多组件的共性异常链路。
四、错误分析与聚合查询
聚焦失败场景,挖掘高频错误及业务影响范围
- 各环境高频错误统计
YourLogTable | where success == false | extend ErrorMsg = tostring(errorMessage), Environment = tostring(einviornment) | summarize ErrorCount = count() by Environment, ErrorMsg | sort by ErrorCount desc
统计不同环境下的高频错误类型,快速定位系统共性问题。
- 错误对业务数据的影响分析
YourLogTable | where success == false | extend DebtorID = tostring(businessKeys.debtorID), ErrorMsg = tostring(errorMessage), TargetSystem = tostring(componentProperties.target) | summarize AffectedDebtors = dcount(DebtorID), ErrorCount = count() by TargetSystem, ErrorMsg | sort by ErrorCount desc
分析不同目标系统下的错误影响范围,量化业务数据受影响程度。
内容的提问来源于stack exchange,提问作者Jonas K
相关产品推荐
相关产品推荐

