You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure资源图KQL查询仅返回当月首日之前数据,参数还是数据限制?

KQL查询结果异常:仅返回当月第一天之前数据的排查

你的问题大概率是参数设置错误,而非数据限制问题,具体排查点如下:

1. 日期筛选条件的优化(逻辑正确但易混淆)

你当前的时间范围条件changeTime < ago(1h) and changeTime > ago(1h)-90d逻辑上是成立的,范围是「当前时间减90天1小时」到「当前时间减1小时」,但更清晰且不易出错的写法建议用between:

changeTime between (ago(90d) .. ago(1h))

两种写法效果几乎一致,但后者可读性更强,能避免因运算符空格、日期运算顺序导致的潜在解析问题。

2. Inner Join导致的有效数据丢失(核心问题)

你使用了两次inner join,而resources表存储的是当前存在的资源状态,并非历史资源记录:

  • 对于Delete类型的变更事件:资源被删除后会从resources表中移除,inner join会直接过滤掉这些记录
  • 对于当月创建后又被删除的Create事件:同样会因为资源不在resources表中被过滤

这就导致当月的变更事件中,只有「创建后一直存在的资源」能被保留,其余事件全部丢失,看起来像是仅返回当月第一天之前的数据。

解决办法

如果需要保留所有变更事件(包括已删除资源的记录),将inner join改为left join即可:

resourcechanges
| extend 
     changeTime = todatetime(properties.changeAttributes.timestamp)
    ,changeType = tostring(properties.changeType)    
    ,changedBy = tostring(properties.changeAttributes.changedBy)
    ,targetResourceType = tostring(properties.targetResourceType)
    ,targetResourceId = tostring(properties.targetResourceId)
| where changeType in ('Create','Delete') and changeTime between (ago(90d) .. ago(1h))
| join kind=left (resources | project resources_Name = name, resources_Type = type, resources_Subscription= subscriptionId, resources_ResourceGroup= resourceGroup, id) on $left.targetResourceId == $right.id 
| join kind=left (resourceContainers | where type=='microsoft.resources/subscriptions' | project SubName=name, subscriptionId, subproperties=properties) on $left.resources_Subscription == $right.subscriptionId
| project resources_Name, resources_Type, resources_Subscription,SubName, resources_ResourceGroup, targetResourceId ,changeTime, changeType, changedBy

3. 验证数据限制的方法

若怀疑是数据保留限制,可单独运行变更事件的基础查询,查看是否存在当月数据:

resourcechanges
| extend changeTime = todatetime(properties.changeAttributes.timestamp)
| where changeTime between (ago(90d) .. ago(1h))
| summarize 事件数量=count() by 日期=bin(changeTime, 1d)
| sort by 日期 desc

如果该查询也没有当月数据,说明resourcechanges表的数据保留期仅到当月第一天,需要调整数据保留策略;若有当月数据,就确认是join逻辑导致的问题。

内容的提问来源于stack exchange,提问作者Rajesh Rajamani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 23:32:35