如何在Application Insights中通过KQL查询获取结果的原始文本?
问题
在Azure门户的Application Insights中执行如下KQL查询:
exceptions | where timestamp > ago(24h) | summarize Count=count() by type | sort by Count desc | take 5 | join kind=inner ( exceptions | where timestamp > ago(24h) ) on type
执行后返回多列数据,但希望获取每个结果项的原始文本以便复制使用,不习惯列视图,询问是否有函数、查询方式或格式可实现该需求。
解决方案
1. 修改查询将整行转为文本
在查询末尾添加转换逻辑,把每行所有字段打包成可复制的JSON格式文本:
exceptions | where timestamp > ago(24h) | summarize Count=count() by type | sort by Count desc | take 5 | join kind=inner ( exceptions | where timestamp > ago(24h) ) on type // 将整行数据转为JSON字符串 | project RawText = tostring(pack_all())
pack_all() 会把当前行的所有字段打包成动态对象,tostring() 将其转为纯文本格式,最终结果仅保留RawText列,每一行都是完整的原始数据内容,直接复制即可。
2. 利用门户导出功能
无需修改查询,直接在查询结果面板操作:
- 点击结果面板顶部的导出按钮(向下箭头图标)
- 选择
CSV或JSON格式导出,下载后即可获取完整的原始文本内容,方便复制使用。
3. 自定义拼接特定字段文本
如果仅需提取部分字段的原始文本,可使用strcat()拼接指定字段:
exceptions | where timestamp > ago(24h) | summarize Count=count() by type | sort by Count desc | take 5 | join kind=inner ( exceptions | where timestamp > ago(24h) ) on type // 自定义拼接需要的字段内容 | project RawText = strcat("类型: ", type, ", 数量: ", Count, ", 时间戳: ", timestamp, ", 异常信息: ", message)
这种方式可以按需定义输出的文本格式,精准提取关键内容。
内容的提问来源于stack exchange,提问作者vemund
相关产品推荐
相关产品推荐

