Azure Log Analytics警报周期抑制及Azure DevOps Bug自动创建需求
基于Azure Log Analytics警报的功能扩展方案
背景
我们通过Azure DevOps Pipeline在多环境中部署基于Azure Log Analytics查询的警报规则,已实现自定义Pipeline遍历查询参数并生成带特定参数的查询逻辑,当前ARM模板部署的警报系统运行正常。
待实现功能
- 功能1:团队处理完问题后,可将警报规则自动抑制指定时长,到期后自动恢复激活,替代手动禁用/启用的人工操作方式。
- 功能2:警报触发时,利用Azure Alert发送的JSON payload,在Azure DevOps中自动创建Bug并分配给对应应用团队;若已有活跃Bug则不重复创建,重复触发时自动更新Bug描述中的触发次数。
当前使用的ARM模板
{ "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "actionGroupName": { "type": "string" }, "query": { "type": "string" }, "logAnalyticsWorkspaceId": { "type": "string" }, "AlertRuleName": { "type": "string" }, "tags": { "type": "object" }, "schedule": { "type": "object" }, "severity": { "type": "int" }, "operator": { "type": "string" }, "threshold": { "type": "int" }, "autoMitigate": { "type": "string", "defaultValue": false }, "enabled": { "type": "string" }, "customWebhookPayload": { "type": "object" }, "location": { "defaultValue": "[resourceGroup().location]", "type": "string" } }, "resources":[ { "type":"Microsoft.Insights/scheduledQueryRules", "name": "[parameters('AlertRuleName')]", "apiVersion": "2018-04-16", "location": "[parameters('location')]", "tags": "[parameters('tags')]", "properties":{ "displayName": "[parameters('AlertRuleName')]", "description": "[parameters('AlertRuleName')]", "enabled": "[parameters('enabled')]", "source": { "query": "[parameters('query')]", "dataSourceId": "[parameters('logAnalyticsWorkspaceId')]", "queryType":"ResultCount" }, "schedule":"[parameters('schedule')]", "action":{ "odata.type": "Microsoft.WindowsAzure.Management.Monitoring.Alerts.Models.Microsoft.AppInsights.Nexus.DataContracts.Resources.ScheduledQueryRules.AlertingAction", "severity": "[parameters('severity')]", "aznsAction":{ "customWebhookPayload": "{ \"AlertRuleName\":\"#alertrulename\", \"AlertType\":\"#alerttype\", \"Severity\":\"#severity\", \"Application\":\"#{appname}#\", \"Text\":\"#alertrulename fired with #searchresultcount records. #{alertDescription}#\", \"SearchQuery\":\"#searchquery\" }", "actionGroup": "[array(parameters('actionGroupName'))]" }, "trigger":{ "thresholdOperator": "[parameters('operator')]", "threshold": "[parameters('threshold')]" } } } } ] }
功能实现方案
功能1:自动抑制/激活警报规则
无需手动跟踪时间,可通过以下两种方式实现:
利用Azure Logic Apps定时控制
在警报的Action Group中添加Logic Apps动作,当团队标记问题已处理时(如通过Teams消息、Azure DevOps工作项状态变更触发),执行以下流程:- 调用Azure Monitor REST API禁用目标警报规则,将请求体中
enabled字段设为false - 添加延迟动作,设置指定的抑制时长(如24小时)
- 延迟结束后,再次调用API将
enabled设为true,恢复警报激活
可在Logic Apps中添加权限验证,确保仅指定团队能触发该流程。
- 调用Azure Monitor REST API禁用目标警报规则,将请求体中
修改警报查询添加临时过滤逻辑
通过自定义日志表实现抑制逻辑:- 创建自定义日志表(如
AlertSuppressionLogs),记录警报规则名称、抑制开始时间、抑制时长 - 修改警报查询,先查询该日志表获取当前警报的抑制状态,若处于抑制期则返回0条结果,避免触发警报
- 团队处理问题时,向该日志表写入抑制记录,到期后无需手动操作,查询会自动恢复正常判断。
- 创建自定义日志表(如
功能2:Azure DevOps自动创建/更新Bug
通过Azure Logic Apps或Azure Functions接收Webhook payload,实现Bug的创建与更新:
- 接收并解析payload
在Action Group中添加Logic Apps或Azure Functions作为Webhook端点,接收Alert发送的JSON payload,提取AlertRuleName、Severity、Application等关键信息。 - 查询活跃Bug
调用Azure DevOps REST API,过滤标题匹配AlertRuleName且状态未关闭/未解决的工作项,检查是否存在对应警报的活跃Bug。 - 创建或更新Bug
- 若不存在活跃Bug:调用API创建Bug,设置标题为
AlertRuleName,描述包含首次触发时间、payload信息,根据Application字段分配给对应团队 - 若已存在活跃Bug:调用API更新Bug描述,追加触发次数和最新触发时间,如在描述末尾添加
"第X次触发:YYYY-MM-DD HH:MM:SS"
- 若不存在活跃Bug:调用API创建Bug,设置标题为
- 权限配置
为Logic Apps/Functions配置Azure DevOps个人访问令牌(PAT),确保拥有工作项的创建、更新权限。
内容的提问来源于stack exchange,提问作者Vowneee
相关产品推荐
相关产品推荐

