如何修改KQL查询筛选内存增量超过1000MiB的记录?
问题分析与解决方案
你遇到的问题有两个核心原因:
- 通过
parse提取的IncreMem_MiB默认是字符串类型,直接和数值1000比较不会生效; union的第二个分支没有IncreMem_MiB字段,这部分记录的该字段值为null,会干扰过滤逻辑。
修改后的完整查询
traces | where timestamp > ago(1d) | where message startswith_cs "memory_profiler_logs:" | parse message with "memory_profiler_logs: " LineNumber " " TotalMem_MiB " " IncreMem_MiB_str " " Occurrences " " Contents // 将字符串类型的内存值转为数值类型 | extend IncreMem_MiB = toreal(IncreMem_MiB_str) | union ( traces | where timestamp > ago(1d) | where message startswith_cs "memory_profiler_logs: Filename: " | parse message with "memory_profiler_logs: Filename: " FileName | project timestamp, FileName, itemId ) // 过滤内存增量大于1000MiB的记录,同时排除无该字段的记录 | where isnotnull(IncreMem_MiB) and IncreMem_MiB > 1000 | project timestamp, LineNumber=iff(FileName != "", FileName, LineNumber), TotalMem_MiB, IncreMem_MiB, Occurrences, Contents, RequestId=itemId | order by timestamp asc
可选调整
如果你需要保留union第二个分支的记录(即带文件名的日志),仅过滤第一个分支中内存增量≤1000MiB的记录,可将过滤条件改为:
| where isnull(IncreMem_MiB) or IncreMem_MiB > 1000
内容的提问来源于stack exchange,提问作者JavierC
相关产品推荐
相关产品推荐

