You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

高级KQL查询执行报错排查:文件创建重命名关联查询异常

问题分析与修正方案

你的查询存在逻辑偏差和性能问题,这是导致报错的主要原因,以下是具体问题和修正后的查询:

原查询核心问题

  1. 逻辑偏离需求:你要展示的是「文件创建后短时间被删除/重命名」,但原查询却关联了DeviceProcessEvents(进程事件),这完全无关,反而引入大量无效数据。
  2. Join键过于宽泛:仅用DeviceId关联两个大表,会产生海量笛卡尔积,直接导致查询资源耗尽,触发“意外错误”。
  3. 时间过滤时机错误:在Join后才过滤时间范围,会让Join处理远超必要的数据量,加重性能负担。
  4. 字段匹配不合理:FolderPath == FolderPath1会漏掉文件重命名时路径变化的场景。

修正后的查询(匹配你的需求)

如果目标是追踪exe文件创建后5分钟内被删除/重命名的行为,使用DeviceFileEvents自关联即可,无需跨表Join:

DeviceFileEvents
| where Timestamp > ago(3d)
// 筛选出exe文件的创建事件
| where ActionType == "FileCreated" and FileName endswith ".exe"
| project CreatedTimestamp = Timestamp, DeviceId, DeviceName, CreatedFileName = FileName, CreatedFolderPath = FolderPath, AccountName
// 自关联同设备下的文件删除/重命名事件
| join kind=inner (
    DeviceFileEvents
    | where Timestamp > ago(3d)
    | where ActionType in ("FileDeleted", "FileRenamed")
    | project ModifiedTimestamp = Timestamp, DeviceId, ModifiedActionType = ActionType, ModifiedFileName = FileName, PreviousFileName, ModifiedFolderPath = FolderPath
) on DeviceId
// 匹配文件:创建的文件等于删除的文件,或重命名前的文件是创建的文件
| where CreatedFileName == ModifiedFileName or CreatedFileName == PreviousFileName
// 确保修改事件在创建事件之后,且间隔不超过5分钟
| where ModifiedTimestamp > CreatedTimestamp and (ModifiedTimestamp - CreatedTimestamp) < timespan(5m)
| extend TimeDifference = ModifiedTimestamp - CreatedTimestamp
| project CreatedTimestamp, CreatedFileName, ModifiedActionType, ModifiedFileName, PreviousFileName, TimeDifference, DeviceName, CreatedFolderPath, AccountName
| order by CreatedTimestamp desc

补充:如果你的实际需求是「文件创建后被执行,随后短时间被删除/重命名」

若你误写了需求,实际要追踪创建→执行→删除/重命名的完整链路,可使用以下查询(分步骤缩小数据集,避免性能问题):

// 1. 提取exe文件的创建事件
let fileCreates = DeviceFileEvents
| where Timestamp > ago(3d)
| where ActionType == "FileCreated" and FileName endswith ".exe"
| project CreatedTimestamp = Timestamp, DeviceId, FileName, FolderPath, AccountName;

// 2. 提取exe文件的执行事件
let fileExecutions = DeviceProcessEvents
| where Timestamp > ago(3d)
| where FileName endswith ".exe"
| project ExecutedTimestamp = Timestamp, DeviceId, FileName, FolderPath, InitiatingProcessFileName, InitiatingProcessParentFileName, ProcessCommandLine, SHA256;

// 3. 提取exe文件的删除/重命名事件
let fileModifications = DeviceFileEvents
| where Timestamp > ago(3d)
| where ActionType in ("FileDeleted", "FileRenamed")
| where FileName endswith ".exe" or PreviousFileName endswith ".exe"
| project ModifiedTimestamp = Timestamp, DeviceId, ActionType, FileName, PreviousFileName, FolderPath;

// 4. 关联三个数据集,追踪完整链路
fileCreates
| join kind=inner fileExecutions on DeviceId, FileName, FolderPath
| where ExecutedTimestamp > CreatedTimestamp and (ExecutedTimestamp - CreatedTimestamp) < timespan(5m)
| join kind=inner fileModifications on DeviceId
| where (FileName == FileName1 or FileName == PreviousFileName1)
| where ModifiedTimestamp > ExecutedTimestamp and (ModifiedTimestamp - ExecutedTimestamp) < timespan(5m)
| extend CreateToExecute = ExecutedTimestamp - CreatedTimestamp, ExecuteToModify = ModifiedTimestamp - ExecutedTimestamp
| project CreatedTimestamp, ExecutedTimestamp, ModifiedTimestamp, CreateToExecute, ExecuteToModify, DeviceId, FileName, FolderPath, AccountName, InitiatingProcessFileName, InitiatingProcessParentFileName, ProcessCommandLine, SHA256, ActionType1
| order by CreatedTimestamp desc

内容的提问来源于stack exchange,提问作者sl0th

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 16:47:05