在Application Insights日志中关联Requests与Traces表排查500错误及SQL问题
Application Insights关联Requests与Traces查询500错误及SQL异常
在Application Insights的日志分析中,requests和traces表默认通过operation_Id字段关联——这是同一个请求链路下所有日志共享的唯一标识。以下是直接可用的查询语句,用于定位返回500的请求及对应的SQL错误日志:
// 筛选500错误请求并关联对应的SQL相关跟踪日志 requests | where resultCode == "500" // 可选:添加时间范围过滤,减少数据量 // | where timestamp between (ago(24h) and now()) | join kind=inner ( traces // 匹配包含SQL操作或异常的日志,可根据实际关键词调整 | where message contains "SQL" or message contains "Exception" or message contains "Error" ) on operation_Id // 选择需要展示的关键字段 | project 时间戳 = timestamp, 请求ID = operation_Id, 请求URL = url, 响应码 = resultCode, 跟踪日志 = message, 客户端IP = client_IP, 用户ID = userId | order by 时间戳 desc
关键说明
join kind=inner确保只返回既有500请求记录又有对应跟踪日志的条目- 可根据实际场景调整
traces中的过滤关键词,比如针对SQL语法错误可改为message contains "Invalid syntax",针对超时改为message contains "Timeout" - 如果
traces表中包含异常堆栈信息,可在project中添加details字段查看完整报错内容
内容的提问来源于stack exchange,提问作者HPAmaris
相关产品推荐
相关产品推荐

