Azure Sentinel:如何获取Playbook运行失败、动作失败及连接断开通知
Azure Sentinel中Playbook/Logic Apps故障排查与日志查询优化
核心排查需求
需要监控并查询以下三类异常场景:
- Playbook整体运行失败
- Playbook/Logic Apps内部动作执行失败
- Playbook连接断开
先解决日志捕获不全的前提问题
如果AzureDiagnostics中仅能捕获极少部分Logic Apps,首先要确认目标Logic Apps的诊断设置已正确开启:
- 进入目标Logic Apps资源页,打开「诊断设置」
- 确保已启用诊断日志,且将
WorkflowRuntime、WorkflowAction、WorkflowTrigger等关键日志类别发送到Azure Sentinel关联的Log Analytics工作区
针对三类场景的KQL查询
1. 查找Playbook运行失败记录
AzureDiagnostics | where ResourceType == "MICROSOFT.LOGIC/WORKFLOWS" | where OperationName == "Microsoft.Logic/workflows/workflowRunCompleted" | where status_s == "Failed" | extend LogicAppName = tostring(split(ResourceId, '/')[8]) | extend RunId = workflowRunId_s | extend IncidentId = extract(@"Incident\/(.*?)\/", 1, correlation_clientTrackingId_s) | project TimeGenerated, LogicAppName, RunId, IncidentId, status_s, errorMessage_s, ResourceId
2. 查找Playbook/Logic Apps动作执行失败记录
AzureDiagnostics | where ResourceType == "MICROSOFT.LOGIC/WORKFLOWS" | where OperationName == "Microsoft.Logic/workflows/workflowActionCompleted" | where status_s == "Failed" | extend LogicAppName = tostring(split(ResourceId, '/')[8]) | extend ActionName = actionName_s | extend RunId = workflowRunId_s | extend IncidentId = extract(@"Incident\/(.*?)\/", 1, correlation_clientTrackingId_s) | project TimeGenerated, LogicAppName, ActionName, RunId, IncidentId, status_s, errorMessage_s, correlation_clientTrackingId_s
3. 查找Playbook连接断开/连接失败记录
AzureDiagnostics | where ResourceType == "MICROSOFT.LOGIC/WORKFLOWS" | where OperationName contains "Connection" and status_s == "Failed" | extend LogicAppName = tostring(split(ResourceId, '/')[8]) | extend ConnectionName = connectionName_s | extend ErrorType = errorType_s | project TimeGenerated, LogicAppName, ConnectionName, ErrorType, errorMessage_s, ResourceId
优化原有查询的问题
你当前的查询仅捕获少量Logic Apps,主要原因包括:
- 未限定
ResourceType,混入了非Logic Apps的无关日志 OperationName模糊匹配范围过大,精准度不足- 部分Logic Apps未开启诊断日志,需按前文步骤补全配置
优化后的通用查询(覆盖更多场景):
AzureDiagnostics | where ResourceType == "MICROSOFT.LOGIC/WORKFLOWS" | where OperationName in ("Microsoft.Logic/workflows/workflowRunCompleted", "Microsoft.Logic/workflows/workflowActionCompleted", "Microsoft.Logic/workflows/connectionCompleted") | extend LogicApp = tostring(split(ResourceId,'/')[8]) | extend IncidentNumber = toint(extract(@"Incident\/(\d+)\/", 1, correlation_clientTrackingId_s)) | summarize Resource = strcat_array(make_set(Resource), ', '), Status = strcat_array(make_set(status_s), ', ') by LogicApp, IncidentNumber, OperationName, Level, TimeGenerated | sort by TimeGenerated desc
配置异常通知告警
针对上述查询结果,可在Azure Sentinel中创建自定义分析规则实现自动通知:
- 进入Azure Sentinel「分析」页面,点击「创建」→「自定义规则」
- 将目标KQL查询作为规则的查询语句
- 设置触发条件(比如5分钟内出现1次失败记录)
- 配置通知方式(通过自动化规则调用通知类Playbook,或直接设置邮件/Teams告警)
内容的提问来源于stack exchange,提问作者HarriS
相关产品推荐
相关产品推荐

