部署Azure多区域DCR遇属性值类型错误求助
解决Azure DCR部署时的类型错误:字符串与对象不匹配
问题根源
你在部署DCR时使用for_each循环创建多区域资源,但引用module.dce和module.law的输出时,错误地将它们当作单个对象处理——实际上这两个模块是实例映射(因使用for_each生成)。此外,DCE模块的输出名称是dce_id而非id,导致引用路径不匹配。
具体修复步骤
修改project\monitor.tf中的azurerm_monitor_data_collection_rule资源定义,修正所有引用路径:
resource "azurerm_monitor_data_collection_rule" "dcr-windows-eventlogs" { for_each = var.locations name = "${each.key}-${var.company_prefix}-dcr-win-eventlogs-infra" resource_group_name = module.rg.resource_group_name location = each.value.region # 直接使用当前区域的region值 data_collection_endpoint_id = module.dce[each.key].dce_id # 通过each.key索引对应区域的DCE实例,使用正确输出名dce_id kind = "Windows" destinations { log_analytics { workspace_resource_id = module.law[each.key].workspace_id # 索引对应区域的LAW实例 name = module.law[each.key].workspace_name # 索引对应区域的LAW实例 } } data_sources { windows_event_log { streams = ["Microsoft-Event"] x_path_queries = ["Application!*[System[(Level=1 or Level=2 or Level=3)]]", "Security!*[System[(band(Keywords,13510798882111488))]]", "System!*[System[(Level=1 or Level=2 or Level=3)]]"] name = "eventLogsDataSource" } } data_flow { streams = ["Microsoft-Event"] destinations = [module.law[each.key].workspace_name] # 去掉引号,直接引用LAW名称作为目标名 } }
额外优化建议
为模块变量添加类型约束:在
modules\law\variables.tf和modules\monitor\dce\variables.tf中,为所有变量添加明确类型(如type = string),避免潜在类型问题:
例如在modules\law\variables.tf中:variable "name" { type = string description = "The name of the Log Analytics workspace." } variable "location" { type = string description = "The location of the Log Analytics workspace." }添加DCE模块的location输出:若希望DCR位置与DCE严格一致,可在
modules\monitor\dce\outputs.tf中添加:output "location" { value = azurerm_monitor_data_collection_endpoint.dce.location }之后在DCR中使用
location = module.dce[each.key].location。
验证修复
执行terraform plan检查是否仍有类型错误,确认所有引用均指向正确的字符串值而非对象。
内容的提问来源于stack exchange,提问作者Cyborganizer
相关产品推荐
相关产品推荐

