You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kusto中JSON数组列拆分为多行的查询问题求助

Kusto mv-expand 无效果的排查与解决方案

核心问题排查与修复步骤

1. 确认Entities列的类型为动态(dynamic)

mv-expand仅对**动态类型(dynamic)**的数组生效。如果你的Entities列存储的是字符串格式的JSON(而非原生dynamic类型),直接使用mv-expand不会有任何变化,必须先将其转换为动态类型:

// 将字符串类型的JSON转为dynamic数组
YourSourceTable
| project 
    其他保留列1, 
    其他保留列2, 
    Entities = parse_json(Entities) // 关键:转换为动态类型
| mv-expand Entities kind=array with_empty=true

2. 强制保留空数组对应的行

默认情况下,mv-expand会过滤掉Entities为空数组的行。要保留这些行并将EntityId/EntityName设为空,必须添加with_empty=true参数(配合kind=array):

// 完整示例:展开数组+保留空行+处理空值
YourSourceTable
| project 
    LogId, 
    EventTime, 
    Entities = parse_json(Entities) // 确保是动态类型
| mv-expand Entities kind=array with_empty=true // 保留空数组的行
| project 
    LogId, 
    EventTime,
    EntityId = coalesce(tostring(Entities.EntityId), ""), // 空数组时转为空字符串
    EntityName = coalesce(tostring(Entities.EntityName), "")

3. 处理非数组的动态类型

如果Entities列的动态类型不是数组(比如是单个JSON对象),mv-expand也不会拆分,需要先将其包装为数组:

// 处理单个对象的情况
YourSourceTable
| project 
    其他列, 
    Entities = parse_json(Entities)
// 将单个对象转为数组,确保统一格式
| extend Entities = iff(gettype(Entities) != "array", dynamic([Entities]), Entities)
| mv-expand Entities kind=array with_empty=true
| project ...

效果说明

  • 非空数组:每个数组元素会生成单独一行,保留所有原列数据
  • 空数组:保留原行,EntityId和EntityName为空字符串
  • 单个对象:转为数组后拆分出一行,对应对象的字段值

内容的提问来源于stack exchange,提问作者Tomek Cybulski

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 16:53:14