You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Kusto查询跨所有AKS Pod的单线程消息处理时长

解决按Pod分组计算CDC日志时间差的Kusto查询问题

直接给出适配所有Pod的完整Kusto查询语句:

ContainerLogV2
| where TimeGenerated > ago(2h)
| where PodName starts_with "<common pod prefix>"
| where LogMessage contains "received:"
// 按Pod拆分分组,每组内独立计算上一条日志时间
| partition by PodName (
    order by TimeGenerated desc
    | extend prev_tg = prev(TimeGenerated)
)
// 解析日志中的源表名称
| parse LogMessage with * "dbo." TABLE_NAME '"}' *
// 生成包含Pod标识的性能分析结果
| project 
    TimeGenerated,
    PodName,
    TABLE_NAME,
    diff = abs(prev_tg - TimeGenerated)/1s
// 过滤每组中无前置记录的第一条日志
| where isnotnull(diff)

关键修改说明

  • partition by PodName:将日志数据按Pod拆分为独立分组,后续的排序和prev()函数仅在组内生效,确保时间差计算的是同一Pod内的上一条日志,而非全局所有日志的上一条。
  • 保留PodName字段:结果中明确标识每条记录所属的Pod,方便横向对比不同Pod的处理性能。
  • 时间差计算逻辑保持一致:通过abs(prev_tg - TimeGenerated)/1s将时间差转换为秒级数值,便于直观分析。

查询结果示例

TimeGeneratedPodNameTABLE_NAMEdiff
2024-06-21 13:34:27-suffixATABLE_ONE60
2024-06-21 13:33:27-suffixATABLE_TWO1
2024-06-21 13:33:26-suffixATABLE_THREE0.2538925
2024-06-21 13:35:10-suffixBTABLE_FOUR3.5
2024-06-21 13:35:06.5-suffixBTABLE_FIVE0.8

内容的提问来源于stack exchange,提问作者lettucemode

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 22:50:04