KQL查询优化:过滤重复容器日志,仅保留单条特定错误
解决方案
以下是调整后的KQL查询,可实现仅保留"Could not find prepared statement"类错误的1条记录,同时保留其他所有不同错误的需求:
let ContainerIdList = KubePodInventory | where ContainerName contains "acc-c1-logger" | where Namespace has "prd" | where ClusterId =~ '/subscriptions/xxxx/resourcegroups/xxxx/providers/Microsoft.ContainerService/managedClusters/aksprd' | distinct ContainerID; ContainerLog | where ContainerID in (ContainerIdList) | where LogEntry !has "SRV1174" | where LogEntry has "| E |" or LogEntry has "| F |" | where LogEntry !contains "the I/O interface definition of project" | where LogEntry !contains "the I/O interface definition of cuc" | where TimeGenerated > ago(5m) | project LogEntrySource, LogEntry, TimeGenerated | order by TimeGenerated desc | top 1000 by LogEntry // 拆分日志字段 | extend SplitLog = split(LogEntry, "|") | project C1 = SplitLog[0], cc=SplitLog[1], C2 = todatetime(SplitLog[1]), C3 = SplitLog[2], C4 = SplitLog[3], C5=SplitLog[4], logerror=SplitLog[5] // 生成分组键:针对目标错误统一分组,其他错误按原始内容分组 | extend group_key = iif( logerror has "Could not find prepared statement", "Could not find prepared statement", tostring(logerror) ) // 按分组键保留最新的一条记录 | summarize arg_max(C2, *) by group_key | project-away group_key, logerror // 拼接最终错误输出 | project ERROR = strcat(cc, "|", C3, "|", C4, "|", C5, "|", SplitLog[5])
关键调整说明
- 新增分组键
group_key:使用iif()函数判断错误内容是否包含目标字符串,将所有"Could not find prepared statement"类错误归为同一分组,其他错误则保留原始错误内容作为分组依据。 - 按分组键去重:通过
summarize arg_max(C2, *) by group_key,针对每个分组保留时间最新的一条记录,既实现了目标错误的去重,又保留了其他不同错误的所有记录。 - 修正原查询笔误:原查询中
logerror1属于未定义字段,调整为SplitLog[5](对应拆分后的错误内容字段)。
内容的提问来源于stack exchange,提问作者ramesh reddy
相关产品推荐
相关产品推荐

