求助:通过KQL存储函数转换Sentinel日志TimeGenerated格式
问题解决方法
核心问题&修正方案
你的代码无法运行主要有两个原因:
- KQL是大小写敏感的,存储函数定义的是小写
dt,但主查询里用了大写DT,两者匹配不上 - 重复调用时区转换函数既冗余又容易出错,而且其实不用自己写月份映射函数,KQL原生就支持生成英文全称月份
简化后的存储函数
直接用format_datetime的内置格式就能生成你要的日期样式,省去自定义月份映射的麻烦:
let dt = (x: datetime) { let local_time = datetime_utc_to_local(x, 'Asia/Singapore'); format_datetime(local_time, "d MMMM yyyy, hh:mm:ss tt") // 如果需要强制加上SGT时区标识,改成下面这行 // strcat(format_datetime(local_time, "d MMMM yyyy, hh:mm:ss tt"), " SGT") };
如果坚持要用自己写的GetMonth函数,修正大小写和重复计算后的版本如下:
let GetMonth = view(Month: int) { case( Month == 1, "January", Month == 2, "February", Month == 3, "March", Month == 4, "April", Month == 5, "May", Month == 6, "June", Month == 7, "July", Month == 8, "August", Month == 9, "September", Month == 10, "October", Month == 11, "November", Month == 12, "December", "") }; let dt = (x: datetime) { let local_time = datetime_utc_to_local(x, 'Asia/Singapore'); strcat( dayofmonth(local_time), " ", GetMonth(monthofyear(local_time)), " ", datetime_part("Year", local_time), " ", format_datetime(local_time, 'hh:mm:ss tt'), " SGT" ) };
正确的主查询调用
注意函数名要和存储函数定义的一致(小写dt):
<table> | where Computer == "datahouse01" and Activity == "Deletion of Records" and DestinationUserName == "FVO44ad" | extend TimeGenerated = dt(TimeGenerated)
补充说明
format_datetime的格式参数里,d代表不带前导零的日期,MMMM代表月份英文全称,yyyy是四位年份,hh:mm:ss tt是12小时制带AM/PM标识的时间- 把时区转换后的时间存为变量
local_time,避免重复计算,既提升查询效率也减少出错概率
内容的提问来源于stack exchange,提问作者Edw
相关产品推荐
相关产品推荐

