如何使用Search-AzGraph查询资源关联的Application Insights
批量查询Azure资源关联的Application Insights配置
我需要生成一份报表,展示指定资源组中所有资源关联的Application Insights实例,以此排查是否存在未配置或配置错误的情况。比如在门户里能看到函数应用的AI关联信息,但我想批量查询所有相关资源的这个配置。
我尝试用Azure Resource Graph查询,通过InstrumentationKey做左连接关联AI资源,但发现只有AI资源本身能返回InstrumentationKey,像函数应用、服务总线这类已配置AI的资源,用tostring(properties.InstrumentationKey)根本拿不到值。
当前尝试的查询代码
第一次尝试的关联查询:
$query = "Resources | where resourceGroup in ($resourceGroupFilter) | extend OS = case(tolower(properties.reserved) == 'true', 'Linux', tolower(properties.reserved) == 'false', 'Windows', '$notApplicable') | extend HttpsOnly = properties.httpsOnly or properties.supportsHttpsTrafficOnly | extend PublicAccess = properties.allowBlobPublicAccess | extend MinTLS = properties.minimumTlsVersion | extend Settings = properties.SiteConfig | extend InstrumentationKey = tostring(properties.InstrumentationKey) | join kind=leftouter (Resources | where type == 'microsoft.insights/components' | project InstrumentationKey = tostring(properties.InstrumentationKey)) on InstrumentationKey | order by name asc" $resources = Search-AzGraph -query $query
单独查询InstrumentationKey的代码:
$query = "Resources | where resourceGroup in ($resourceGroupFilter) | extend OS = case(tolower(properties.reserved) == 'true', 'Linux', tolower(properties.reserved) == 'false', 'Windows', '$notApplicable') | extend HttpsOnly = properties.httpsOnly or properties.supportsHttpsTrafficOnly | extend PublicAccess = properties.allowBlobPublicAccess | extend MinTLS = properties.minimumTlsVersion | extend Settings = properties.SiteConfig | extend InstrumentationKey = tostring(properties.InstrumentationKey) | order by name asc" $resources = Search-AzGraph -query $query
问题原因及解决方案
不同类型的Azure资源,其关联的Application Insights InstrumentationKey存储的属性路径不一样:
- 函数应用/ Web应用:存储在
properties.siteConfig.appSettings里的APPINSIGHTS_INSTRUMENTATIONKEY - 服务总线:存储在
properties.diagnosticSettings中关联的AI资源ID,而非直接存InstrumentationKey - Application Insights自身:直接存在
properties.InstrumentationKey中
需要针对不同资源类型,分别提取关联的AI信息,再关联AI资源详情。修改后的查询示例:
$query = "Resources | where resourceGroup in ($resourceGroupFilter) | extend OS = case(tolower(properties.reserved) == 'true', 'Linux', tolower(properties.reserved) == 'false', 'Windows', '$notApplicable') | extend HttpsOnly = properties.httpsOnly or properties.supportsHttpsTrafficOnly | extend PublicAccess = properties.allowBlobPublicAccess | extend MinTLS = properties.minimumTlsVersion | extend Settings = properties.SiteConfig # 针对不同资源类型提取InstrumentationKey或AI资源ID | extend AI_InstrumentationKey = case( type == 'microsoft.web/sites' or type == 'microsoft.web/functions', tostring(parse_json(properties.siteConfig.appSettings)[APPINSIGHTS_INSTRUMENTATIONKEY]), type == 'microsoft.insights/components', tostring(properties.InstrumentationKey), '' ) | extend AI_ResourceId = case( type contains 'microsoft.servicebus', tostring(properties.diagnosticSettings[0].workspaceId), # 适配服务总线诊断设置关联的AI资源ID '' ) # 左连接AI资源,关联名称和完整ID | join kind=leftouter ( Resources | where type == 'microsoft.insights/components' | project AI_InstrumentationKey = tostring(properties.InstrumentationKey), AI_ResourceName = name, AI_ResourceId = id ) on AI_InstrumentationKey | order by name asc" $resources = Search-AzGraph -query $query
补充说明
- 针对服务总线这类通过诊断设置关联AI的资源,需要根据实际配置调整
diagnosticSettings的筛选逻辑(比如多个诊断设置时需指定目标AI的条目); - 如果资源是通过资源ID直接关联AI,可通过AI资源的ID字段反向匹配关联信息;
- 可以根据业务需要扩展更多资源类型的提取逻辑,确保覆盖所有需要检查的资源类别。
内容的提问来源于stack exchange,提问作者Jeremy
相关产品推荐
相关产品推荐

