You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Log Analytics创建集成仪表板并编写事务追踪聚合查询?

Log Analytics集成仪表板查询思路(基于给定日志结构)

一、核心结果聚合查询

用于生成仪表板总览类指标,展示整体事务处理情况

  1. 按环境+组件+数据类型统计事务成功率
YourLogTable
| extend Environment = tostring(einviornment), Component = tostring(sourceComponent), DataCategory = tostring(componentProperties.data)
| summarize 
    TotalTransactions = count(),
    SuccessCount = countif(success == true),
    FailureCount = countif(success == false),
    SuccessRate = round(SuccessCount * 100.0 / TotalTransactions, 2)
by Environment, Component, DataCategory
| sort by Environment, Component

该查询可生成各环境下不同组件处理各类数据的核心指标,适合用卡片、柱状图展示,快速定位低成功率的组件或数据类型。

  1. 按时间维度的事务趋势统计
YourLogTable
| extend Environment = tostring(einviornment), SuccessStatus = iif(success == true, "成功", "失败")
| summarize TransactionCount = count() by bin(TimeGenerated, 1h), Environment, SuccessStatus
| sort by TimeGenerated asc

按小时粒度统计不同环境的成功/失败事务量变化,用折线图展示可直观观察流量波动、异常峰值时段。

二、组件维度事务跟踪查询

聚焦单个组件的处理细节,定位子组件或特定业务场景的问题

  1. 单个主组件下子组件事务统计
YourLogTable
| where sourceComponent == "目标组件名称"
| extend SubComponent = tostring(subSourceComponent), Environment = tostring(einviornment)
| summarize 
    Total = count(),
    Failures = countif(success == false)
by Environment, SubComponent
| sort by Failures desc

查看指定主组件下各子工作流的处理表现,快速定位出错率高的子组件。

  1. 组件失败事务的业务字段关联
YourLogTable
| extend Component = tostring(sourceComponent), DebtorID = tostring(businessKeys.debtorID), TargetSystem = tostring(componentProperties.target)
| where success == false
| project TimeGenerated, Component, DebtorID, TargetSystem, errorMessage
| sort by TimeGenerated desc

筛选组件的失败事务并关联业务关键字段(如debtorID),便于直接定位受影响的业务数据。

三、全链路事务跟踪查询

利用correlationID实现跨组件的事务流转追踪

  1. 单个事务的全链路详情
YourLogTable
| where correlationID == "指定关联ID"
| extend 
    Component = tostring(sourceComponent),
    SubComponent = tostring(subSourceComponent),
    SourceSystem = tostring(componentProperties.source),
    TargetSystem = tostring(componentProperties.target),
    Status = iif(success == true, "成功", "失败")
| project TimeGenerated, Status, Component, SubComponent, SourceSystem, TargetSystem, executionID, errorMessage
| sort by TimeGenerated asc

输入具体的correlationID,还原该事务在各个组件间的完整流转路径、每个节点的状态及错误信息。

  1. 异常链路批量排查
YourLogTable
| where success == false
| extend CorrelationID = tostring(correlationID)
| join kind=inner (
    YourLogTable
    | extend CorrelationID = tostring(correlationID)
    | summarize ComponentFlow = make_set(sourceComponent) by CorrelationID
) on CorrelationID
| project TimeGenerated, CorrelationID, ComponentFlow, errorMessage, businessKeys.debtorID
| sort by TimeGenerated desc

批量找出所有失败事务的跨组件流转路径,快速定位涉及多组件的共性异常链路。

四、错误分析与聚合查询

聚焦失败场景,挖掘高频错误及业务影响范围

  1. 各环境高频错误统计
YourLogTable
| where success == false
| extend ErrorMsg = tostring(errorMessage), Environment = tostring(einviornment)
| summarize ErrorCount = count() by Environment, ErrorMsg
| sort by ErrorCount desc

统计不同环境下的高频错误类型,快速定位系统共性问题。

  1. 错误对业务数据的影响分析
YourLogTable
| where success == false
| extend 
    DebtorID = tostring(businessKeys.debtorID),
    ErrorMsg = tostring(errorMessage),
    TargetSystem = tostring(componentProperties.target)
| summarize AffectedDebtors = dcount(DebtorID), ErrorCount = count() by TargetSystem, ErrorMsg
| sort by ErrorCount desc

分析不同目标系统下的错误影响范围,量化业务数据受影响程度。

内容的提问来源于stack exchange,提问作者Jonas K

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 16:12:39