You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修改Kusto Query批量检查ZScaler上的多个URL启用状态?

批量检查ZScaler中多个URL的Kusto查询修改方案

要实现批量检查700多个URL/域名,你可以通过动态数组匹配或数据表关联两种方式修改查询,避免逐个执行的低效问题:

方法1:使用has_any配合动态数组

直接将所有需要检查的域名/URL片段放入动态数组,通过has_any匹配任意符合条件的记录:

CommonSecurityLog
| where DeviceVendor == "Zscaler"
| where DeviceEventCategory == "Global Allow"
// 替换为你的700个目标域名/URL片段,用双引号包裹、逗号分隔
| where DestinationHostName has_any (dynamic(["amazonaws.com", "example.com", "test.org"]))
// 按请求URL和域名分组统计,便于查看每个目标的匹配情况
| summarize count() by RequestURL, DestinationHostName
| sort by count_ desc
  • 若需精确匹配完整RequestURL,可将条件改为RequestURL in (dynamic(["https://xxx.com", "https://yyy.com"]))。
  • has_any适合匹配包含指定片段的记录,in适合精确匹配完整字符串。

方法2:使用datatable管理大量目标(推荐)

当目标条目超过数百个时,用datatable单独定义检查列表,更便于维护和修改:

// 定义要检查的URL/域名列表,每行一条,格式为 "目标值"
let targetList = datatable(target:string) [
    "amazonaws.com",
    "example.com",
    "test.org",
    // 继续添加剩余的700个条目
];
CommonSecurityLog
| where DeviceVendor == "Zscaler"
| where DeviceEventCategory == "Global Allow"
// 关联目标列表,筛选包含目标值的记录
| join kind=inner (targetList) on $left.DestinationHostName contains $right.target
// 按请求URL和目标值分组统计
| summarize count() by RequestURL, target
| sort by count_ desc
  • 这种方式将目标列表与查询逻辑分离,修改时只需调整targetList部分,避免主查询混乱。
  • 若需精确匹配,将contains替换为==即可。

内容的提问来源于stack exchange,提问作者Jasneet Singh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 02:25:05