You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署Azure多区域DCR遇属性值类型错误求助

解决Azure DCR部署时的类型错误:字符串与对象不匹配

问题根源

你在部署DCR时使用for_each循环创建多区域资源,但引用module.dce和module.law的输出时,错误地将它们当作单个对象处理——实际上这两个模块是实例映射(因使用for_each生成)。此外,DCE模块的输出名称是dce_id而非id,导致引用路径不匹配。

具体修复步骤

修改project\monitor.tf中的azurerm_monitor_data_collection_rule资源定义,修正所有引用路径:

resource "azurerm_monitor_data_collection_rule" "dcr-windows-eventlogs" {
  for_each = var.locations

  name                        = "${each.key}-${var.company_prefix}-dcr-win-eventlogs-infra"
  resource_group_name         = module.rg.resource_group_name
  location                    = each.value.region # 直接使用当前区域的region值
  data_collection_endpoint_id = module.dce[each.key].dce_id # 通过each.key索引对应区域的DCE实例,使用正确输出名dce_id
  kind                        = "Windows"

  destinations {
    log_analytics {
      workspace_resource_id = module.law[each.key].workspace_id # 索引对应区域的LAW实例
      name                  = module.law[each.key].workspace_name # 索引对应区域的LAW实例
    }
  }

  data_sources {
    windows_event_log {
      streams = ["Microsoft-Event"]
      x_path_queries = ["Application!*[System[(Level=1 or Level=2 or Level=3)]]", "Security!*[System[(band(Keywords,13510798882111488))]]", "System!*[System[(Level=1 or Level=2 or Level=3)]]"]
      name = "eventLogsDataSource"
    }
  }

  data_flow {
    streams      = ["Microsoft-Event"]
    destinations = [module.law[each.key].workspace_name] # 去掉引号,直接引用LAW名称作为目标名
  }
}

额外优化建议

  1. 为模块变量添加类型约束:在modules\law\variables.tf和modules\monitor\dce\variables.tf中,为所有变量添加明确类型(如type = string),避免潜在类型问题:
    例如在modules\law\variables.tf中:

    variable "name" {
      type        = string
      description = "The name of the Log Analytics workspace."
    }
    
    variable "location" {
      type        = string
      description = "The location of the Log Analytics workspace."
    }
    
  2. 添加DCE模块的location输出:若希望DCR位置与DCE严格一致,可在modules\monitor\dce\outputs.tf中添加:

    output "location" {
      value = azurerm_monitor_data_collection_endpoint.dce.location
    }
    

    之后在DCR中使用location = module.dce[each.key].location。

验证修复

执行terraform plan检查是否仍有类型错误,确认所有引用均指向正确的字符串值而非对象。

内容的提问来源于stack exchange,提问作者Cyborganizer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 12:35:00