You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

KQL查询协助:如何筛选指向公网的默认路由表?

筛选包含公网默认路由的路由表

问题说明

需要筛选出存在公网默认路由(地址前缀为0.0.0.0/0、下一跳类型为Internet)的路由表,但原有查询未做有效过滤,返回了所有路由表内容。

原有查询的问题

原有查询中通过extend addressPrefix = "0.0.0.0/0"和extend nextHopType = "Internet"是直接硬设置字段值,而非过滤符合条件的路由规则,因此无法筛选出目标路由表。

修正后的Kusto查询

resources
| where type =~ "Microsoft.Network/routeTables"
| mv-expand rules = properties.routes
// 过滤出符合公网默认路由的规则
| where rules.properties.addressPrefix == "0.0.0.0/0" 
  and rules.properties.nextHopType == "Internet"
| join kind=leftouter (
    resourcecontainers 
    | where type == 'microsoft.resources/subscriptions' 
    | project SubscriptionName=name, subscriptionId
) on subscriptionId
// 更可靠的子网名称提取逻辑
| extend subnet_name = iff(array_length(properties.subnets) > 0, split(properties.subnets[0].id, '/')[8], "")
// 直接从路由规则中读取字段,而非硬赋值
| extend addressPrefix = rules.properties.addressPrefix
| extend nextHopType = rules.properties.nextHopType
| extend nextHopIpAddress = tostring(rules.properties.nextHopIpAddress)
| extend hasBgpOverride = tostring(rules.properties.hasBgpOverride)
| extend provisioningState = tostring(rules.properties.provisioningState)
| extend udrname = rules.name
| extend rtname = name
| project SubscriptionName, resourceGroup, subnet_name, rtname, udrname, addressPrefix, nextHopType, nextHopIpAddress, provisioningState, hasBgpOverride
| sort by SubscriptionName, resourceGroup asc, rtname asc, addressPrefix asc

关键修改点

  • 添加where条件,仅保留路由规则中地址前缀为0.0.0.0/0且下一跳类型为Internet的条目
  • 修正子网名称提取逻辑,避免原split索引越界问题,通过子网ID的拆分获取名称
  • 去掉硬赋值的addressPrefix和nextHopType,直接从路由规则属性中读取对应值

内容的提问来源于stack exchange,提问作者vb312

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 16:03:27