You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Kusto查询排除含指定值的动态字典行(日期时间/整数/双精度)

Kusto查询:排除包含指定值的动态字典行

要实现排除包含指定值的整行动态字典数据,核心思路是提取字典中的所有值,检查是否包含目标值,再过滤掉符合条件的行。以下针对日期时间、整数、双精度三种类型分别给出实现方案:

通用逻辑说明

使用bag_values()函数提取动态字典的所有值,结合has_any()进行值匹配,注意类型统一匹配(比如日期时间需用datetime类型比对,避免字符串格式差异导致的误判)。


示例1:日期时间类型动态字典

假设数据表名为DateTimeData,动态字典列名为DictCol,要排除的目标值为datetime(2024-08-12T02:33:33.6740000Z):

DateTimeData
| extend DictValues = bag_values(DictCol)
| where not(DictValues has_any(datetime(2024-08-12T02:33:33.6740000Z)))
| project-away DictValues

说明:

  • bag_values(DictCol)会自动将字典中的日期时间字符串转为datetime类型
  • has_any()精准匹配目标时间值,not()取反实现排除包含该值的行

示例2:整数类型动态字典

假设数据表名为IntegerData,动态字典列名为DictCol,要排除的目标值为2001:

IntegerData
| extend DictValues = bag_values(DictCol)
| where not(DictValues has_any(2001))
| project-away DictValues

说明:

  • 整数类型直接用数值匹配即可,has_any()会严格比对整数值,不会出现类型隐式转换问题

示例3:双精度类型动态字典

假设数据表名为DoubleData,动态字典列名为DictCol,要排除的目标值为10.297:

DoubleData
| extend DictValues = bag_values(DictCol)
| where not(DictValues has_any(10.297))
| project-away DictValues

说明:

  • 双精度类型直接匹配即可;若存在浮点数精度差异,可先对值做round()处理后再比对,比如:
    DoubleData
    | extend DictValues = bag_values(DictCol)
    | where not(DictValues has_any(round(10.297, 3)))
    | project-away DictValues
    

复用封装(可选)

如果需要多次复用该逻辑,可以创建自定义函数简化调用:

.create-or-alter function exclude_dict_row(table_name: string, dict_col: string, exclude_value: dynamic) {
    table(table_name)
    | extend DictValues = bag_values(todynamic(dict_col))
    | where not(DictValues has_any(exclude_value))
    | project-away DictValues
}

调用示例:

exclude_dict_row("DateTimeData", "DictCol", datetime(2024-08-12T02:33:33.6740000Z))

内容的提问来源于stack exchange,提问作者Bala

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 00:48:20