You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Sentinel:如何获取Playbook运行失败、动作失败及连接断开通知

Azure Sentinel中Playbook/Logic Apps故障排查与日志查询优化

核心排查需求

需要监控并查询以下三类异常场景:

  • Playbook整体运行失败
  • Playbook/Logic Apps内部动作执行失败
  • Playbook连接断开

先解决日志捕获不全的前提问题

如果AzureDiagnostics中仅能捕获极少部分Logic Apps,首先要确认目标Logic Apps的诊断设置已正确开启:

  1. 进入目标Logic Apps资源页,打开「诊断设置」
  2. 确保已启用诊断日志,且将WorkflowRuntime、WorkflowAction、WorkflowTrigger等关键日志类别发送到Azure Sentinel关联的Log Analytics工作区

针对三类场景的KQL查询

1. 查找Playbook运行失败记录

AzureDiagnostics
| where ResourceType == "MICROSOFT.LOGIC/WORKFLOWS"
| where OperationName == "Microsoft.Logic/workflows/workflowRunCompleted"
| where status_s == "Failed"
| extend LogicAppName = tostring(split(ResourceId, '/')[8])
| extend RunId = workflowRunId_s
| extend IncidentId = extract(@"Incident\/(.*?)\/", 1, correlation_clientTrackingId_s)
| project TimeGenerated, LogicAppName, RunId, IncidentId, status_s, errorMessage_s, ResourceId

2. 查找Playbook/Logic Apps动作执行失败记录

AzureDiagnostics
| where ResourceType == "MICROSOFT.LOGIC/WORKFLOWS"
| where OperationName == "Microsoft.Logic/workflows/workflowActionCompleted"
| where status_s == "Failed"
| extend LogicAppName = tostring(split(ResourceId, '/')[8])
| extend ActionName = actionName_s
| extend RunId = workflowRunId_s
| extend IncidentId = extract(@"Incident\/(.*?)\/", 1, correlation_clientTrackingId_s)
| project TimeGenerated, LogicAppName, ActionName, RunId, IncidentId, status_s, errorMessage_s, correlation_clientTrackingId_s

3. 查找Playbook连接断开/连接失败记录

AzureDiagnostics
| where ResourceType == "MICROSOFT.LOGIC/WORKFLOWS"
| where OperationName contains "Connection" and status_s == "Failed"
| extend LogicAppName = tostring(split(ResourceId, '/')[8])
| extend ConnectionName = connectionName_s
| extend ErrorType = errorType_s
| project TimeGenerated, LogicAppName, ConnectionName, ErrorType, errorMessage_s, ResourceId

优化原有查询的问题

你当前的查询仅捕获少量Logic Apps,主要原因包括:

  • 未限定ResourceType,混入了非Logic Apps的无关日志
  • OperationName模糊匹配范围过大,精准度不足
  • 部分Logic Apps未开启诊断日志,需按前文步骤补全配置

优化后的通用查询(覆盖更多场景):

AzureDiagnostics
| where ResourceType == "MICROSOFT.LOGIC/WORKFLOWS"
| where OperationName in ("Microsoft.Logic/workflows/workflowRunCompleted", "Microsoft.Logic/workflows/workflowActionCompleted", "Microsoft.Logic/workflows/connectionCompleted")
| extend LogicApp = tostring(split(ResourceId,'/')[8])
| extend IncidentNumber = toint(extract(@"Incident\/(\d+)\/", 1, correlation_clientTrackingId_s))
| summarize 
    Resource = strcat_array(make_set(Resource), ', '),
    Status = strcat_array(make_set(status_s), ', ')
by LogicApp, IncidentNumber, OperationName, Level, TimeGenerated
| sort by TimeGenerated desc

配置异常通知告警

针对上述查询结果,可在Azure Sentinel中创建自定义分析规则实现自动通知:

  1. 进入Azure Sentinel「分析」页面,点击「创建」→「自定义规则」
  2. 将目标KQL查询作为规则的查询语句
  3. 设置触发条件(比如5分钟内出现1次失败记录)
  4. 配置通知方式(通过自动化规则调用通知类Playbook,或直接设置邮件/Teams告警)

内容的提问来源于stack exchange,提问作者HarriS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 20:05:00