Azure Resource Graph中KQL关联查询VM与Standard_LRS磁盘结果异常求助
问题原因分析及解决方案
可能的原因
仅关联操作系统磁盘,遗漏数据磁盘
你的查询只提取了虚拟机的OS磁盘ID进行关联,但部分目标虚拟机可能仅数据磁盘为Standard_LRS类型,OS磁盘是其他类型。这类虚拟机因主查询未包含数据磁盘ID,无法与子查询的Standard_LRS磁盘匹配,导致被遗漏。默认Inner Join过滤了非OS盘匹配的记录
KQL的join默认使用Inner Join,仅保留两边完全匹配的记录。若虚拟机的Standard_LRS磁盘是数据盘(未在主查询的id字段中出现),则会被过滤掉,无法出现在结果中。磁盘ID存在格式/大小写差异
极少数情况下,虚拟机返回的磁盘ID(properties.storageProfile.osDisk.managedDisk.id)与磁盘资源本身的id字段存在大小写或格式差异,导致关联匹配失败。
修正后的查询
以下查询会捕获虚拟机的所有磁盘(OS盘+数据盘),并通过左外关联确保所有使用Standard_LRS磁盘的虚拟机都被返回:
resources | where type == "microsoft.compute/virtualmachines" and subscriptionId == "xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxx" // 合并OS盘和数据盘的ID到一个数组 | extend disks = array_concat( pack_array(properties.storageProfile.osDisk.managedDisk.id), properties.storageProfile.dataDisks | array_map(x => x.managedDisk.id) ) // 展开数组,让每个磁盘ID对应一条虚拟机记录 | mv-expand disks to typeof(string) | project vm_name=name, disk_id=disks // 使用左外关联,避免过滤掉数据盘匹配的虚拟机 | join kind=leftouter ( resources | where type == "microsoft.compute/disks" and subscriptionId == "xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxx" and sku.name == "Standard_LRS" | project disk_id=id, disk_type=sku.name ) on disk_id // 仅保留匹配到Standard_LRS磁盘的记录 | where isnotnull(disk_type) // 去重同一虚拟机的重复磁盘记录 | distinct vm_name, disk_id, disk_type
内容的提问来源于stack exchange,提问作者esa
相关产品推荐
相关产品推荐

