You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Log Analytics联合查询中Success属性始终为空的原因排查

为什么Union多个表后Success属性为空?

这问题我熟!你的第一个查询里用了union AppTraces | union AppExceptions | union AppRequests,但这三个表中只有AppRequests表包含Success字段——AppTraces和AppExceptions根本就没有这个属性。当你把它们Union到一起时,来自后两个表的记录自然填充不上Success的值,所以你看到这个字段是空的。而第二个查询只针对AppRequests表查询,Success字段自然能正常工作。

解决思路与修改方案

你可以通过两种方式修复这个问题:

方案1:给无Success字段的表补默认值

用extend给AppTraces和AppExceptions手动添加Success字段,并根据日志类型设置合理的默认值(比如异常和错误日志直接设为false):

union 
  (AppTraces | extend Success = false),
  (AppExceptions | extend Success = false),
  (AppRequests)
| where AppRoleName has "-NEU" 
| where TimeGenerated > ago(1d) 
| order by TimeGenerated asc 
| project 
    Success, 
    TimeGenerated, 
    AppRoleName, 
    message = iff(Message != '', Message, iff(InnermostMessage != '', InnermostMessage, Properties.['prop__{OriginalFormat}'])), 
    logLevel = Properties.['LogLevel'] 
| where logLevel != "Information"

方案2:先过滤再Union(更贴合你的需求)

如果你的核心目标是获取失败相关的日志,可以先筛选出AppRequests中Success == "false"的记录,再和异常、非信息类日志Union,最后用coalesce统一处理Success字段的空值:

union 
  (AppTraces | where Properties.['LogLevel'] != "Information"),
  (AppExceptions),
  (AppRequests | where Success == "false")
| where AppRoleName has "-NEU" 
| where TimeGenerated > ago(1d) 
| order by TimeGenerated asc 
| project 
    Success = coalesce(Success, false),
    TimeGenerated, 
    AppRoleName, 
    message = iff(Message != '', Message, iff(InnermostMessage != '', InnermostMessage, Properties.['prop__{OriginalFormat}'])), 
    logLevel = Properties.['LogLevel']

这样处理后,所有记录的Success字段都会有明确值,不会再出现空的情况啦。

内容的提问来源于stack exchange,提问作者Matt Douhan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 18:17:29