请求协助:实现IISReset Stop后未Start时输出告警数据
解决IISReset停止后未重启的KQL查询方案
要捕获IIS执行iisreset /stop后未执行iisreset /start的场景,你需要调整查询逻辑,不再依赖必须关联成功的Join操作,而是通过**左反连接(leftanti)**找出仅有停止操作、无后续启动操作的事件,或通过union合并成功场景与异常场景的结果。
方案一:直接捕获未重启的异常事件
该查询会筛选出所有执行了iisreset /stop但在后续一段时间内(可自定义)未执行启动命令的事件:
// 定义时间范围:仅检查最近N小时内的事件,避免历史数据干扰 let LookbackWindow = 4h; // 筛选所有IISReset停止事件 let IISStopEvents = Event | where TimeGenerated > ago(LookbackWindow) | where EventID == 4688 // 进程创建事件,需根据实际环境的事件ID调整 | where CommandLine has_any ("iisreset.exe", "iisreset") | where CommandLine contains "/stop" | project StopTime = TimeGenerated, Computer, StopCommand = CommandLine; // 筛选所有IISReset启动事件 let IISStartEvents = Event | where TimeGenerated > ago(LookbackWindow) | where EventID == 4688 | where CommandLine has_any ("iisreset.exe", "iisreset") | where CommandLine contains "/start" | project StartTime = TimeGenerated, Computer; // 找出有停止但无后续启动的事件 IISStopEvents | leftanti join IISStartEvents on Computer // 确保启动事件不会早于停止事件(避免跨时间窗口的误判) | where isnull(IISStartEvents.StartTime) or IISStartEvents.StartTime <= StopTime | project StopTime, Computer, StopCommand, "IIS停止后未执行重启" as AlarmStatus
方案二:合并成功与异常场景的完整查询
如果需要同时展示IISReset成功重启和未重启的情况,可通过union将原有成功查询与异常查询合并,确保即使成功查询无数据,异常场景的结果也能正常返回:
let LookbackWindow = 4h; // 原有成功重启的查询逻辑 let SuccessfulResets = Event | where TimeGenerated > ago(LookbackWindow) | where EventID == 4688 | where CommandLine has_any ("iisreset.exe", "iisreset") | parse CommandLine with * "iisreset" Operation: string // 解析操作类型 | where Operation in ("/stop", "/start") | summarize StopTime = minif(TimeGenerated, Operation == "/stop"), StartTime = maxif(TimeGenerated, Operation == "/start") by Computer | where isnotempty(StopTime) and isnotempty(StartTime) and StartTime > StopTime | project Computer, StopTime, StartTime, "IIS重启成功" as Status; // 未重启的异常查询逻辑 let UnrestartedResets = Event | where TimeGenerated > ago(LookbackWindow) | where EventID == 4688 | where CommandLine has_any ("iisreset.exe", "iisreset") and CommandLine contains "/stop" | project StopTime = TimeGenerated, Computer, StopCommand = CommandLine | leftanti join ( Event | where TimeGenerated > ago(LookbackWindow) | where EventID == 4688 | where CommandLine has_any ("iisreset.exe", "iisreset") and CommandLine contains "/start" | project StartTime = TimeGenerated, Computer ) on Computer | where isnull(StartTime) or StartTime <= StopTime | project Computer, StopTime, StartTime = datetime(null), "IIS停止后未重启" as Status; // 合并两个结果集,确保异常场景始终能被输出 union SuccessfulResets, UnrestartedResets
关键逻辑说明
- leftanti连接:会保留左侧表(停止事件)中,在右侧表(启动事件)中找不到匹配项的记录,正好对应“有停止无启动”的异常场景。
- 时间范围限制:通过
ago(LookbackWindow)缩小查询范围,减少不必要的计算,同时避免误报历史事件。 - union合并:确保无论成功重启的事件是否存在,未重启的异常事件都会被输出,满足告警配置的需求。
内容的提问来源于stack exchange,提问作者AUser
相关产品推荐
相关产品推荐

