You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Event Hub至ADX日志摄入失败求助:BadRequest_NoRecordsOrWrongFormat错误

解决Azure Event Hub到ADX摄入失败(BadRequest_NoRecordsOrWrongFormat)的问题

从你的描述来看,核心问题出在Event Hub中的消息格式不符合ADX的JSON要求,这也是你切换其他格式也失败的原因。下面一步步帮你排查和解决:

1. 修正消息格式:使用标准JSON

你提供的示例数据是类似PowerShell的键值对语法(source = "xxx"; ci = "xxx";),但ADX的JSON格式要求每个消息必须是有效的JSON对象。把你的示例数据转换成标准JSON:

{
  "source": "SCOM 2019 - LoadTest:$Set1Random",
  "ci": "AWSGOBUG123-DBINS",
  "ip_address": "11.200.98.$_",
  "override_change": "no",
  "priority": "Normal",
  "scom_severity": "critical",
  "assignment_group": " ",
  "assigned_to": " ",
  "short_description": "The IIS 10 Application Pool named .NET v4.5 on is unavailable as the Application Pool has been stopped",
  "description": "Some Description: $LoadRun",
  "identifier": "ID:$Set1Random",
  "override_monitor_flag": "false",
  "object_id": " ",
  "action": "create",
  "monitor_details": "AA",
  "url": " ",
  "alert_id": "AlertId:StaticAlertId",
  "event_time": "(Get-Date).ToShortDateString()"
}

如果是批量发送消息,使用MultiJson格式时,需要每行一个独立的JSON对象(不要用数组包裹),比如:

{"source":"xxx", "ci":"xxx"}
{"source":"yyy", "ci":"yyy"}

2. 优化摄入映射配置

你的IngestionMapping中datatype字段留空了,虽然ADX会自动推断类型,但为了避免意外,建议补全和表结构一致的类型:

[
  {"column":"source","datatype":"string","Path":"$.source"},
  {"column":"ci","datatype":"string","Path":"$.ci"},
  {"column":"ip_address","datatype":"string","Path":"$.ip_address"},
  {"column":"override_change","datatype":"string","Path":"$.override_change"},
  {"column":"priority","datatype":"string","Path":"$.priority"},
  {"column":"scom_severity","datatype":"string","Path":"$.scom_severity"},
  {"column":"assignment_group","datatype":"string","Path":"$.assignment_group"},
  {"column":"assigned_to","datatype":"string","Path":"$.assigned_to"},
  {"column":"short_description","datatype":"string","Path":"$.short_description"},
  {"column":"description","datatype":"string","Path":"$.description"},
  {"column":"identifier","datatype":"string","Path":"$.identifier"},
  {"column":"override_monitor_flag","datatype":"string","Path":"$.override_monitor_flag"},
  {"column":"object_id","datatype":"string","Path":"$.object_id"},
  {"column":"action","datatype":"string","Path":"$.action"},
  {"column":"monitor_details","datatype":"string","Path":"$.monitor_details"},
  {"column":"url","datatype":"string","Path":"$.url"},
  {"column":"alert_id","datatype":"string","Path":"$.alert_id"},
  {"column":"event_time","datatype":"string","Path":"$.event_time"}
]

3. 验证配置并测试

  • 确认摄入格式设置:如果发送单条JSON对象,把摄入连接的格式设为Json;如果是每行一个JSON对象,设为MultiJson。
  • 手动测试摄入:用ADX的.ingest inline命令快速验证数据格式是否正确,比如:
    .ingest inline into table EventHubRaw with (format=json) <|
    {"source": "SCOM 2019 - LoadTest:$Set1Random", "ci": "AWSGOBUG123-DBINS", "ip_address": "11.200.98.$_"}
    
    如果这条命令成功,说明数据格式和映射是没问题的,问题就出在Event Hub中的消息格式。
  • 检查Event Hub消息内容:用Event Hub的内置查看工具确认实际发送的消息确实是标准JSON,没有语法错误(比如遗漏逗号、引号不匹配等)。

4. 进阶排查(如果以上步骤无效)

  • 开启详细错误报告:把ValidationPolicy中的IsDetailedErrorReportingEnabled设为True,这样ADX会返回更具体的错误信息,比如哪条消息格式错误、具体的语法问题。
  • 检查压缩设置:如果消息是压缩的,确保ZipPattern配置正确,或者暂时关闭压缩测试。
  • 确认消费者组:ADX使用的Event Hub消费者组是否唯一,有没有其他服务在消费同一组的消息导致ADX无法获取完整数据。

内容的提问来源于stack exchange,提问作者avani jain

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 23:02:41