如何通过KQL移除Azure容器日志重复项并保留最新错误条目
修复KQL查询实现错误日志去重并保留最新条目
原查询的问题在于最后使用distinct LogEntry仅能去重日志内容,但会丢失时间戳等关键信息,且无法确保保留的是最新的那条记录;同时top 1000 by LogEntry的排序逻辑并不能帮你按错误内容分组筛选最新条目。
以下是修改后的查询,核心是利用arg_max()函数按错误内容分组,保留每组中时间戳最新的完整日志记录:
let ContainerIdList = KubePodInventory | where ContainerName contains "custom-app-logger" | where Namespace has "devns" | where ClusterId =~ '/subscriptions/12345-xyzl-4e12-bc3a-5c7859365342636/resourcegroups/rg-aks-dev-dev/providers/Microsoft.ContainerService/managedClusters/aksdevcluster' | distinct ContainerID; ContainerLog | where ContainerID in (ContainerIdList) | where LogEntry !has "SRV1174" | where LogEntry has "| E |" or LogEntry has "| F |" | where LogEntry !contains "the I/O interface definition of project" | where LogEntry !contains "the I/O interface definition of cuc" | project LogEntrySource, LogEntry, TimeGenerated // 按LogEntry分组,保留每组中时间最新的完整记录 | summarize arg_max(TimeGenerated, *) by LogEntry // 按时间倒序排列,最新的错误显示在最上方 | order by TimeGenerated desc | render table
关键改动说明:
- 移除了原查询中无效的
top 1000 by LogEntry和distinct LogEntry,替换为summarize arg_max(TimeGenerated, *) by LogEntry:该函数会将相同LogEntry的日志归为一组,然后提取每组中TimeGenerated最大(最新)的那条记录,同时保留该记录的所有字段(*表示所有列)。 - 新增
order by TimeGenerated desc确保最终结果按时间倒序展示,最新的错误条目排在最前面。
内容的提问来源于stack exchange,提问作者ramesh reddy
相关产品推荐
相关产品推荐

