Azure资源图KQL查询仅返回当月首日之前数据,参数还是数据限制?
KQL查询结果异常:仅返回当月第一天之前数据的排查
你的问题大概率是参数设置错误,而非数据限制问题,具体排查点如下:
1. 日期筛选条件的优化(逻辑正确但易混淆)
你当前的时间范围条件changeTime < ago(1h) and changeTime > ago(1h)-90d逻辑上是成立的,范围是「当前时间减90天1小时」到「当前时间减1小时」,但更清晰且不易出错的写法建议用between:
changeTime between (ago(90d) .. ago(1h))
两种写法效果几乎一致,但后者可读性更强,能避免因运算符空格、日期运算顺序导致的潜在解析问题。
2. Inner Join导致的有效数据丢失(核心问题)
你使用了两次inner join,而resources表存储的是当前存在的资源状态,并非历史资源记录:
- 对于
Delete类型的变更事件:资源被删除后会从resources表中移除,inner join会直接过滤掉这些记录 - 对于当月创建后又被删除的
Create事件:同样会因为资源不在resources表中被过滤
这就导致当月的变更事件中,只有「创建后一直存在的资源」能被保留,其余事件全部丢失,看起来像是仅返回当月第一天之前的数据。
解决办法
如果需要保留所有变更事件(包括已删除资源的记录),将inner join改为left join即可:
resourcechanges | extend changeTime = todatetime(properties.changeAttributes.timestamp) ,changeType = tostring(properties.changeType) ,changedBy = tostring(properties.changeAttributes.changedBy) ,targetResourceType = tostring(properties.targetResourceType) ,targetResourceId = tostring(properties.targetResourceId) | where changeType in ('Create','Delete') and changeTime between (ago(90d) .. ago(1h)) | join kind=left (resources | project resources_Name = name, resources_Type = type, resources_Subscription= subscriptionId, resources_ResourceGroup= resourceGroup, id) on $left.targetResourceId == $right.id | join kind=left (resourceContainers | where type=='microsoft.resources/subscriptions' | project SubName=name, subscriptionId, subproperties=properties) on $left.resources_Subscription == $right.subscriptionId | project resources_Name, resources_Type, resources_Subscription,SubName, resources_ResourceGroup, targetResourceId ,changeTime, changeType, changedBy
3. 验证数据限制的方法
若怀疑是数据保留限制,可单独运行变更事件的基础查询,查看是否存在当月数据:
resourcechanges | extend changeTime = todatetime(properties.changeAttributes.timestamp) | where changeTime between (ago(90d) .. ago(1h)) | summarize 事件数量=count() by 日期=bin(changeTime, 1d) | sort by 日期 desc
如果该查询也没有当月数据,说明resourcechanges表的数据保留期仅到当月第一天,需要调整数据保留策略;若有当月数据,就确认是join逻辑导致的问题。
内容的提问来源于stack exchange,提问作者Rajesh Rajamani
相关产品推荐
相关产品推荐

