You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将SecurityAlert表中的IP与AzureIPTable中的子网匹配校验

解决方案

要实现从SecurityAlert表中筛选出属于AzureIPTable表子网范围内的IP地址,你可以参考以下修正后的KQL语句:

// 提取SecurityAlert中去重的有效IPv4地址
let TargetIPs = SecurityAlert
| mv-expand parse_json(Entities)
| evaluate bag_unpack(Entities, columnsConflict='keep_source')
| where isnotempty(Address) and ipv4_is_valid(Address)  // 过滤空值和无效IP
| distinct Address;

// 筛选出属于AzureIPTable子网的IP
TargetIPs
| where exists (
    AzureIPTable
    | where ipv4_is_in_range(TargetIPs.Address, addressPrefixes)
)

原语句的问题说明

  1. 函数参数错误:ipv4_is_in_range()的第一个参数需要是单个IP地址,而非整个IP集合,原语句直接传入IPs集合会导致逻辑错误。
  2. 关联逻辑缺失:原语句仅在AzureIPTable中添加列,未建立IP与子网的匹配关联,无法筛选出符合条件的IP。

补充说明

如果需要同时返回对应的子网信息,可以改用join搭配ipv4_is_in_range的方式:

let TargetIPs = SecurityAlert
| mv-expand parse_json(Entities)
| evaluate bag_unpack(Entities, columnsConflict='keep_source')
| where isnotempty(Address) and ipv4_is_valid(Address)
| distinct Address;

TargetIPs
| join kind=inner (AzureIPTable) on $left.Address has_any $right.addressPrefixes
| where ipv4_is_in_range(Address, addressPrefixes)
| project Address, addressPrefixes

内容的提问来源于stack exchange,提问作者HarriS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 12:15:59