You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Azure Resource Graph Explorer查询Azure WAF自定义规则?

解决Azure Resource Graph查询WAF自定义规则的问题

直接查询microsoft.network/applicationgatewaywebapplicationfirewallpolicies/customrules返回0结果的核心原因是:自定义规则不是独立的Azure资源类型,它是嵌套在WAF策略(或应用网关WAF配置)的properties字段中的子属性,无法通过type字段直接定位。

以下是两种场景下的正确KQL查询:

1. 查询独立WAF策略中的自定义规则

resources
| where type == "microsoft.network/applicationgatewaywebapplicationfirewallpolicies"
// 展开嵌套的自定义规则数组,兼容无自定义规则的WAF策略
| mv-expand customRules = properties.customRules default=dynamic([])
// 过滤掉空规则条目(如果需要保留无规则的WAF,可删除此行)
| where array_length(customRules) > 0
// 提取核心规则信息,可按需增减字段
| project
    WAF策略名称 = name,
    资源组 = resourceGroup,
    订阅ID = subscriptionId,
    规则名称 = customRules.name,
    优先级 = customRules.priority,
    执行动作 = customRules.action,
    匹配条件 = customRules.matchConditions,
    规则状态 = customRules.enabledState

2. 查询应用网关内置WAF的自定义规则

如果你的WAF是直接配置在应用网关上(而非独立WAF策略),用下面的查询:

resources
| where type == "microsoft.network/applicationgateways"
// 只筛选启用了WAF的应用网关
| where properties.webApplicationFirewallConfiguration.enabled == true
// 展开自定义规则数组
| mv-expand customRules = properties.webApplicationFirewallConfiguration.customRules default=dynamic([])
| where array_length(customRules) > 0
| project
    应用网关名称 = name,
    资源组 = resourceGroup,
    订阅ID = subscriptionId,
    规则名称 = customRules.name,
    优先级 = customRules.priority,
    执行动作 = customRules.action,
    匹配条件 = customRules.matchConditions,
    规则状态 = customRules.enabledState

额外提示

  • mv-expand后的default=dynamic([])是为了避免没有自定义规则的资源被直接过滤掉,如果你不需要这些条目,可以删除该参数
  • 若要深入解析匹配条件的细节(比如匹配变量、操作符、匹配值),可以在project中进一步提取,例如匹配变量 = customRules.matchConditions.matchVariables

内容的提问来源于stack exchange,提问作者Vehicular IT

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 20:03:21