You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Search-AzGraph查询资源关联的Application Insights

批量查询Azure资源关联的Application Insights配置

我需要生成一份报表,展示指定资源组中所有资源关联的Application Insights实例,以此排查是否存在未配置或配置错误的情况。比如在门户里能看到函数应用的AI关联信息,但我想批量查询所有相关资源的这个配置。

我尝试用Azure Resource Graph查询,通过InstrumentationKey做左连接关联AI资源,但发现只有AI资源本身能返回InstrumentationKey,像函数应用、服务总线这类已配置AI的资源,用tostring(properties.InstrumentationKey)根本拿不到值。

当前尝试的查询代码

第一次尝试的关联查询:

$query = "Resources | where resourceGroup in ($resourceGroupFilter) 
    | extend OS = case(tolower(properties.reserved) == 'true', 'Linux', tolower(properties.reserved) == 'false', 'Windows', '$notApplicable') 
    | extend HttpsOnly = properties.httpsOnly or properties.supportsHttpsTrafficOnly 
    | extend PublicAccess = properties.allowBlobPublicAccess 
    | extend MinTLS = properties.minimumTlsVersion 
    | extend Settings = properties.SiteConfig 
    | extend InstrumentationKey = tostring(properties.InstrumentationKey)
    | join kind=leftouter (Resources | where type == 'microsoft.insights/components' | project InstrumentationKey = tostring(properties.InstrumentationKey)) on InstrumentationKey
    | order by name asc" 

$resources = Search-AzGraph -query $query

单独查询InstrumentationKey的代码:

$query = "Resources | where resourceGroup in ($resourceGroupFilter) 
    | extend OS = case(tolower(properties.reserved) == 'true', 'Linux', tolower(properties.reserved) == 'false', 'Windows', '$notApplicable') 
    | extend HttpsOnly = properties.httpsOnly or properties.supportsHttpsTrafficOnly 
    | extend PublicAccess = properties.allowBlobPublicAccess 
    | extend MinTLS = properties.minimumTlsVersion 
    | extend Settings = properties.SiteConfig 
    | extend InstrumentationKey = tostring(properties.InstrumentationKey)
    | order by name asc" 

$resources = Search-AzGraph -query $query

问题原因及解决方案

不同类型的Azure资源,其关联的Application Insights InstrumentationKey存储的属性路径不一样:

  • 函数应用/ Web应用:存储在properties.siteConfig.appSettings里的APPINSIGHTS_INSTRUMENTATIONKEY
  • 服务总线:存储在properties.diagnosticSettings中关联的AI资源ID,而非直接存InstrumentationKey
  • Application Insights自身:直接存在properties.InstrumentationKey中

需要针对不同资源类型,分别提取关联的AI信息,再关联AI资源详情。修改后的查询示例:

$query = "Resources | where resourceGroup in ($resourceGroupFilter)
    | extend OS = case(tolower(properties.reserved) == 'true', 'Linux', tolower(properties.reserved) == 'false', 'Windows', '$notApplicable')
    | extend HttpsOnly = properties.httpsOnly or properties.supportsHttpsTrafficOnly
    | extend PublicAccess = properties.allowBlobPublicAccess
    | extend MinTLS = properties.minimumTlsVersion
    | extend Settings = properties.SiteConfig
    # 针对不同资源类型提取InstrumentationKey或AI资源ID
    | extend AI_InstrumentationKey = case(
        type == 'microsoft.web/sites' or type == 'microsoft.web/functions',
        tostring(parse_json(properties.siteConfig.appSettings)[APPINSIGHTS_INSTRUMENTATIONKEY]),
        type == 'microsoft.insights/components',
        tostring(properties.InstrumentationKey),
        ''
    )
    | extend AI_ResourceId = case(
        type contains 'microsoft.servicebus',
        tostring(properties.diagnosticSettings[0].workspaceId), # 适配服务总线诊断设置关联的AI资源ID
        ''
    )
    # 左连接AI资源,关联名称和完整ID
    | join kind=leftouter (
        Resources | where type == 'microsoft.insights/components'
        | project AI_InstrumentationKey = tostring(properties.InstrumentationKey),
                  AI_ResourceName = name,
                  AI_ResourceId = id
    ) on AI_InstrumentationKey
    | order by name asc"

$resources = Search-AzGraph -query $query

补充说明

  • 针对服务总线这类通过诊断设置关联AI的资源,需要根据实际配置调整diagnosticSettings的筛选逻辑(比如多个诊断设置时需指定目标AI的条目);
  • 如果资源是通过资源ID直接关联AI,可通过AI资源的ID字段反向匹配关联信息;
  • 可以根据业务需要扩展更多资源类型的提取逻辑,确保覆盖所有需要检查的资源类别。

内容的提问来源于stack exchange,提问作者Jeremy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 23:17:23