You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

KQL查询优化:过滤重复容器日志,仅保留单条特定错误

解决方案

以下是调整后的KQL查询,可实现仅保留"Could not find prepared statement"类错误的1条记录,同时保留其他所有不同错误的需求:

let ContainerIdList = KubePodInventory
    | where ContainerName contains "acc-c1-logger"
    | where Namespace has "prd" 
    | where ClusterId =~ '/subscriptions/xxxx/resourcegroups/xxxx/providers/Microsoft.ContainerService/managedClusters/aksprd'
    | distinct ContainerID;
ContainerLog 
| where ContainerID in (ContainerIdList)
| where LogEntry !has "SRV1174"
| where LogEntry has "| E |" or LogEntry has "| F |"
| where LogEntry !contains "the I/O interface definition of project" 
| where LogEntry !contains "the I/O interface definition of cuc" 
| where TimeGenerated > ago(5m)
| project LogEntrySource, LogEntry, TimeGenerated 
| order by TimeGenerated desc
| top 1000 by LogEntry
// 拆分日志字段
| extend SplitLog = split(LogEntry, "|")
| project 
    C1 = SplitLog[0], 
    cc=SplitLog[1],
    C2 = todatetime(SplitLog[1]), 
    C3 = SplitLog[2], 
    C4 = SplitLog[3], 
    C5=SplitLog[4], 
    logerror=SplitLog[5]
// 生成分组键:针对目标错误统一分组,其他错误按原始内容分组
| extend group_key = iif(
    logerror has "Could not find prepared statement",
    "Could not find prepared statement",
    tostring(logerror)
)
// 按分组键保留最新的一条记录
| summarize arg_max(C2, *) by group_key
| project-away group_key, logerror
// 拼接最终错误输出
| project ERROR = strcat(cc, "|", C3, "|", C4, "|", C5, "|", SplitLog[5])

关键调整说明

  1. 新增分组键group_key:使用iif()函数判断错误内容是否包含目标字符串,将所有"Could not find prepared statement"类错误归为同一分组,其他错误则保留原始错误内容作为分组依据。
  2. 按分组键去重:通过summarize arg_max(C2, *) by group_key,针对每个分组保留时间最新的一条记录,既实现了目标错误的去重,又保留了其他不同错误的所有记录。
  3. 修正原查询笔误:原查询中logerror1属于未定义字段,调整为SplitLog[5](对应拆分后的错误内容字段)。

内容的提问来源于stack exchange,提问作者ramesh reddy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 19:52:36