You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Data Explorer日志日期范围查询报错求助

Azure Data Explorer 日期范围查询错误解决

错误1分析与修复

你第一个查询报错between(): all arguments are expected to have the same type 'long',说明你的timestamp列类型是long(Unix时间戳),而非datetime类型,无法直接和datetime()生成的日期比较。另外你写的日期顺序逻辑错误,between要求左值早于等于右值。

修复后的查询:

  • 若timestamp是毫秒级Unix时间戳:
Logs
| where unixtime_milliseconds_todatetime(timestamp) between (datetime(2022-06-02) .. datetime(2024-06-01))
  • 若timestamp是秒级Unix时间戳:
Logs
| where unixtime_seconds_todatetime(timestamp) between (datetime(2022-06-02) .. datetime(2024-06-01))

错误2分析与修复

第二个查询存在两个问题:

  1. 直接用字符串日期和timestamp比较,类型不匹配,需转为datetime类型;
  2. 'Tickets.Resolved Date'列名如果不属于Logs表,会触发列不存在错误,需确认列名正确性或是否切换到了对应表。

假设你要查询Logs表的timestamp列,修复后的查询:

Logs
| where unixtime_milliseconds_todatetime(timestamp) >= datetime(2020-05-25) 
  and unixtime_milliseconds_todatetime(timestamp) <= datetime(2020-05-26)

(如果是秒级时间戳,替换成unixtime_seconds_todatetime)

额外验证步骤

先确认timestamp列的类型和格式,执行以下查询查看:

Logs
| take 5
| project timestamp, typeof(timestamp)

根据返回的类型(long/string等)调整转换函数。如果是字符串类型的日期,用todatetime(timestamp)转换后再比较。

内容的提问来源于stack exchange,提问作者Jason Solida

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 06:53:12