You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过KQL移除Azure容器日志重复项并保留最新错误条目

修复KQL查询实现错误日志去重并保留最新条目

原查询的问题在于最后使用distinct LogEntry仅能去重日志内容,但会丢失时间戳等关键信息,且无法确保保留的是最新的那条记录;同时top 1000 by LogEntry的排序逻辑并不能帮你按错误内容分组筛选最新条目。

以下是修改后的查询,核心是利用arg_max()函数按错误内容分组,保留每组中时间戳最新的完整日志记录:

let ContainerIdList = KubePodInventory
    | where ContainerName contains "custom-app-logger"
    | where Namespace has "devns"
    | where ClusterId =~ '/subscriptions/12345-xyzl-4e12-bc3a-5c7859365342636/resourcegroups/rg-aks-dev-dev/providers/Microsoft.ContainerService/managedClusters/aksdevcluster'
    | distinct ContainerID;
ContainerLog 
    | where ContainerID in (ContainerIdList)
    | where LogEntry !has "SRV1174"
    | where LogEntry has "| E |" or LogEntry has "| F |"
    | where LogEntry !contains "the I/O interface definition of project" 
    | where LogEntry !contains "the I/O interface definition of cuc" 
    | project LogEntrySource, LogEntry, TimeGenerated 
    // 按LogEntry分组,保留每组中时间最新的完整记录
    | summarize arg_max(TimeGenerated, *) by LogEntry
    // 按时间倒序排列,最新的错误显示在最上方
    | order by TimeGenerated desc
    | render table

关键改动说明:

  • 移除了原查询中无效的top 1000 by LogEntry和distinct LogEntry,替换为summarize arg_max(TimeGenerated, *) by LogEntry:该函数会将相同LogEntry的日志归为一组,然后提取每组中TimeGenerated最大(最新)的那条记录,同时保留该记录的所有字段(*表示所有列)。
  • 新增order by TimeGenerated desc确保最终结果按时间倒序展示,最新的错误条目排在最前面。

内容的提问来源于stack exchange,提问作者ramesh reddy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 00:57:40