You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET 8 API中如何隐藏MSAL 4.64.0的False日志消息?

问题描述

在.NET 8 API项目中,通过Serilog将日志输出至Application Insights时,每次请求都会生成大量包含「False MSAL 4.64.0.0 MSAL.NetCore .NET 8.0.8」的跟踪日志,需要隐藏这类日志。使用ITokenAcquisition获取后端服务令牌,已尝试以下两种配置但均未生效:

  • 在appsettings.json的Logging节点将MSAL.NetCore设为Warning级别
  • 在Serilog配置中添加ByExcluding过滤包含「False MSAL」的消息

相关代码与配置

获取令牌代码片段

accessToken = await _tokenAcquisition.GetAccessTokenForUserAsync(new[] { _configuration["PasApi:ScopeForAccessToken"] });

appsettings.json 原Logging配置

"Logging": {
  "LogLevel": {
     "Default": "Information",
     "Microsoft.AspNetCore": "Warning",
     "MSAL.NetCore": "Warning"
  }
}

原Serilog配置

"Serilog": {
  "MinimumLevel": {
    "Default": "Information",
    "Override": {
      "Microsoft": "Information",
      "Microsoft.AspNetCore": "Warning",
      "System": "Warning"
    }
  },
  "WriteTo": [
  {
    "Name": "ApplicationInsights",
    "Args": { 
       "telemetryConverter": "Serilog.Sinks.ApplicationInsights.TelemetryConverters.TraceTelemetryConverter, Serilog.Sinks.ApplicationInsights"
     }
  }
  ],
  "Filter": [
    {
      "Name": "ByExcluding",
      "Args": {
         "expression": "Contains(@MessageTemplate, 'False MSAL')"
      }
    }
  ]
},

示例日志

False MSAL 4.64.0.0 MSAL.NetCore .NET 8.0.8 Microsoft Windows 10.0.19045 [2024-09-17 09:57:46Z - 4671fb35-5f88-41a6-95f0-6b53f07cf66f] TokenEndpoint: ****

Program.cs 相关代码

builder.Host.UseSerilog((hostingContext, loggerConfiguration) => loggerConfiguration.ReadFrom.Configuration(hostingContext.Configuration));
builder.Services.AddAadRegistration(Configuration);

public static IServiceCollection AddAadRegistration(this IServiceCollection services, IConfiguration configuration)
{
  services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
        .AddMicrosoftIdentityWebApi(configuration.GetSection(AppSettings.AZUREAD))
        .EnableTokenAcquisitionToCallDownstreamApi()
        .AddInMemoryTokenCaches();

  services.Configure<JwtBearerOptions>(JwtBearerDefaults.AuthenticationScheme, options =>
  {
      options.TokenValidationParameters.NameClaimType = @"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress";
  });

  var origins = new List<string>();
  configuration.Bind(AppSettings.CORS_MAIN, origins);

  services.AddCors(options =>
  {
      options.AddPolicy(name: Policies.CORS_MAIN,
        builder => builder.WithOrigins(origins.ToArray())
            .AllowAnyMethod()
            .AllowAnyHeader());
  });

  return services;
}

使用的NuGet包版本

  • Azure.Identity v1.12.0
  • Microsoft.AspNetCore.Authentication.JwtBearer v8.0.8
  • Microsoft.Identity.Client 4.64.0
  • Microsoft.Identity.Web 3.1.0
  • Serilog.AspNetCore 8.0.2
  • Serilog.Sinks.ApplicationInsights 4.0.0
解决方案

1. 修正Serilog过滤表达式

原过滤规则针对@MessageTemplate,但这类日志的内容存储在@Message字段中,需修改过滤条件:

"Filter": [
  {
    "Name": "ByExcluding",
    "Args": {
       "expression": "Contains(@Message, 'False MSAL')"
    }
  }
]

若需更精准过滤(仅排除该内容的Info级日志),可使用:

"expression": "Contains(@Message, 'False MSAL') and @Level = 'Information'"

2. 正确配置MSAL日志级别

MSAL的日志类别是Microsoft.Identity.Client而非MSAL.NetCore,需更新日志级别配置:

方式一:在Serilog配置中添加Override

"Serilog": {
  "MinimumLevel": {
    "Default": "Information",
    "Override": {
      "Microsoft": "Information",
      "Microsoft.AspNetCore": "Warning",
      "System": "Warning",
      "Microsoft.Identity.Client": "Warning" // 新增该行,将MSAL日志设为Warning
    }
  },
  // 其他配置保持不变
}

方式二:修改Logging节点配置

"Logging": {
  "LogLevel": {
     "Default": "Information",
     "Microsoft.AspNetCore": "Warning",
     "Microsoft.Identity.Client": "Warning" // 替换原MSAL.NetCore配置
  }
}

3. 验证效果

修改配置后重启项目,检查Application Insights的跟踪日志,确认「False MSAL」类日志已被过滤。

内容的提问来源于stack exchange,提问作者NiAu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 09:05:59