You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:通过KQL存储函数转换Sentinel日志TimeGenerated格式

问题解决方法

核心问题&修正方案

你的代码无法运行主要有两个原因:

  • KQL是大小写敏感的,存储函数定义的是小写dt,但主查询里用了大写DT,两者匹配不上
  • 重复调用时区转换函数既冗余又容易出错,而且其实不用自己写月份映射函数,KQL原生就支持生成英文全称月份

简化后的存储函数

直接用format_datetime的内置格式就能生成你要的日期样式,省去自定义月份映射的麻烦:

let dt = (x: datetime) {
    let local_time = datetime_utc_to_local(x, 'Asia/Singapore');
    format_datetime(local_time, "d MMMM yyyy, hh:mm:ss tt")
    // 如果需要强制加上SGT时区标识,改成下面这行
    // strcat(format_datetime(local_time, "d MMMM yyyy, hh:mm:ss tt"), " SGT")
};

如果坚持要用自己写的GetMonth函数,修正大小写和重复计算后的版本如下:

let GetMonth = view(Month: int) {
    case(
        Month == 1, "January",
        Month == 2, "February",
        Month == 3, "March",
        Month == 4, "April",
        Month == 5, "May",
        Month == 6, "June",
        Month == 7, "July",
        Month == 8, "August",
        Month == 9, "September",
        Month == 10, "October",
        Month == 11, "November",
        Month == 12, "December",
        "")
};
let dt = (x: datetime) {
    let local_time = datetime_utc_to_local(x, 'Asia/Singapore');
    strcat(
        dayofmonth(local_time), " ",
        GetMonth(monthofyear(local_time)), " ",
        datetime_part("Year", local_time), " ",
        format_datetime(local_time, 'hh:mm:ss tt'),
        " SGT"
    )
};

正确的主查询调用

注意函数名要和存储函数定义的一致(小写dt):

<table>
| where Computer == "datahouse01" and Activity == "Deletion of Records" and DestinationUserName == "FVO44ad"
| extend TimeGenerated = dt(TimeGenerated)

补充说明

  • format_datetime的格式参数里,d代表不带前导零的日期,MMMM代表月份英文全称,yyyy是四位年份,hh:mm:ss tt是12小时制带AM/PM标识的时间
  • 把时区转换后的时间存为变量local_time,避免重复计算,既提升查询效率也减少出错概率

内容的提问来源于stack exchange,提问作者Edw

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 03:17:26