You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求可生成按周统计快照总数的Kusto时间图表查询(原查询失效)

解决Kusto查询生成每周快照总数时间图表的问题

以下是针对你的需求调整后的有效查询,以及原查询可能失效的原因说明:

针对Azure Resource Graph的查询(使用resources表)

如果是在Azure Resource Graph中查询快照资源,原查询可能因空值、未排序或缺少时间范围过滤失效,调整后的查询如下:

resources
| where type == "Microsoft.Compute/snapshots"
| where isnotempty(properties.CreationDate) // 过滤空的创建日期
| extend CreationDate = todatetime(properties.CreationDate)
| where CreationDate > ago(12w) // 限定查询最近12周的数据,可根据需求调整
| summarize TotalSnapshots = count() by WeekStart = bin(CreationDate, 7d)
| sort by WeekStart asc // 按时间升序排列,确保图表时序正确
| render timechart with (title="每周快照总数变化趋势", xcolumn=WeekStart, ycolumn=TotalSnapshots)

针对Log Analytics的查询(使用Snapshots表)

如果你的环境中有Snapshots日志表,原查询可能因时间范围未限定、字段对应错误失效,调整后的查询如下:

Snapshots
| where Timestamp > ago(12w) // 限定时间范围,避免返回过多/空数据
| where isnotempty(Timestamp) // 过滤空时间戳
| summarize TotalSnapshots = count() by WeekStart = bin(Timestamp, 1w)
| sort by WeekStart asc
| render timechart with (title="每周快照总数变化趋势", xcolumn=WeekStart, ycolumn=TotalSnapshots)

原查询失效的常见原因

  • 表/字段不存在:确认Snapshots表是否存在于你的工作区,或resources表中properties.CreationDate字段是否正确(部分环境可能字段名不同)
  • 空值/格式错误:未过滤空的时间字段,或todatetime转换失败导致数据丢失
  • 未排序:聚合后未按时间升序排列,导致图表时序混乱
  • 时间范围问题:未限定查询时间范围,导致返回数据为空或超出可视化范围

内容的提问来源于stack exchange,提问作者user23419269

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 19:22:35