You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求协助:实现IISReset Stop后未Start时输出告警数据

解决IISReset停止后未重启的KQL查询方案

要捕获IIS执行iisreset /stop后未执行iisreset /start的场景,你需要调整查询逻辑,不再依赖必须关联成功的Join操作,而是通过**左反连接(leftanti)**找出仅有停止操作、无后续启动操作的事件,或通过union合并成功场景与异常场景的结果。

方案一:直接捕获未重启的异常事件

该查询会筛选出所有执行了iisreset /stop但在后续一段时间内(可自定义)未执行启动命令的事件:

// 定义时间范围:仅检查最近N小时内的事件,避免历史数据干扰
let LookbackWindow = 4h;

// 筛选所有IISReset停止事件
let IISStopEvents = Event
| where TimeGenerated > ago(LookbackWindow)
| where EventID == 4688 // 进程创建事件,需根据实际环境的事件ID调整
| where CommandLine has_any ("iisreset.exe", "iisreset") 
| where CommandLine contains "/stop"
| project StopTime = TimeGenerated, Computer, StopCommand = CommandLine;

// 筛选所有IISReset启动事件
let IISStartEvents = Event
| where TimeGenerated > ago(LookbackWindow)
| where EventID == 4688
| where CommandLine has_any ("iisreset.exe", "iisreset")
| where CommandLine contains "/start"
| project StartTime = TimeGenerated, Computer;

// 找出有停止但无后续启动的事件
IISStopEvents
| leftanti join IISStartEvents on Computer
// 确保启动事件不会早于停止事件(避免跨时间窗口的误判)
| where isnull(IISStartEvents.StartTime) or IISStartEvents.StartTime <= StopTime
| project StopTime, Computer, StopCommand, "IIS停止后未执行重启" as AlarmStatus

方案二:合并成功与异常场景的完整查询

如果需要同时展示IISReset成功重启和未重启的情况,可通过union将原有成功查询与异常查询合并,确保即使成功查询无数据,异常场景的结果也能正常返回:

let LookbackWindow = 4h;

// 原有成功重启的查询逻辑
let SuccessfulResets = Event
| where TimeGenerated > ago(LookbackWindow)
| where EventID == 4688
| where CommandLine has_any ("iisreset.exe", "iisreset")
| parse CommandLine with * "iisreset" Operation: string // 解析操作类型
| where Operation in ("/stop", "/start")
| summarize 
    StopTime = minif(TimeGenerated, Operation == "/stop"),
    StartTime = maxif(TimeGenerated, Operation == "/start") 
    by Computer
| where isnotempty(StopTime) and isnotempty(StartTime) and StartTime > StopTime
| project Computer, StopTime, StartTime, "IIS重启成功" as Status;

// 未重启的异常查询逻辑
let UnrestartedResets = Event
| where TimeGenerated > ago(LookbackWindow)
| where EventID == 4688
| where CommandLine has_any ("iisreset.exe", "iisreset") and CommandLine contains "/stop"
| project StopTime = TimeGenerated, Computer, StopCommand = CommandLine
| leftanti join (
    Event
    | where TimeGenerated > ago(LookbackWindow)
    | where EventID == 4688
    | where CommandLine has_any ("iisreset.exe", "iisreset") and CommandLine contains "/start"
    | project StartTime = TimeGenerated, Computer
) on Computer
| where isnull(StartTime) or StartTime <= StopTime
| project Computer, StopTime, StartTime = datetime(null), "IIS停止后未重启" as Status;

// 合并两个结果集,确保异常场景始终能被输出
union SuccessfulResets, UnrestartedResets

关键逻辑说明

  • leftanti连接:会保留左侧表(停止事件)中,在右侧表(启动事件)中找不到匹配项的记录,正好对应“有停止无启动”的异常场景。
  • 时间范围限制:通过ago(LookbackWindow)缩小查询范围,减少不必要的计算,同时避免误报历史事件。
  • union合并:确保无论成功重启的事件是否存在,未重启的异常事件都会被输出,满足告警配置的需求。

内容的提问来源于stack exchange,提问作者AUser

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 20:51:23