You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修改KQL查询筛选内存增量超过1000MiB的记录?

问题分析与解决方案

你遇到的问题有两个核心原因:

  1. 通过parse提取的IncreMem_MiB默认是字符串类型,直接和数值1000比较不会生效;
  2. union的第二个分支没有IncreMem_MiB字段,这部分记录的该字段值为null,会干扰过滤逻辑。

修改后的完整查询

traces
| where timestamp > ago(1d)
| where message startswith_cs "memory_profiler_logs:"
| parse message with "memory_profiler_logs: " LineNumber "  " TotalMem_MiB "  " IncreMem_MiB_str "  " Occurrences "  " Contents
// 将字符串类型的内存值转为数值类型
| extend IncreMem_MiB = toreal(IncreMem_MiB_str)
| union (
    traces
    | where timestamp > ago(1d)
    | where message startswith_cs "memory_profiler_logs: Filename: "
    | parse message with "memory_profiler_logs: Filename: " FileName
    | project timestamp, FileName, itemId
)
// 过滤内存增量大于1000MiB的记录,同时排除无该字段的记录
| where isnotnull(IncreMem_MiB) and IncreMem_MiB > 1000
| project timestamp, LineNumber=iff(FileName != "", FileName, LineNumber), TotalMem_MiB, IncreMem_MiB, Occurrences, Contents, RequestId=itemId
| order by timestamp asc

可选调整

如果你需要保留union第二个分支的记录(即带文件名的日志),仅过滤第一个分支中内存增量≤1000MiB的记录,可将过滤条件改为:

| where isnull(IncreMem_MiB) or IncreMem_MiB > 1000

内容的提问来源于stack exchange,提问作者JavierC

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 23:00:03