You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kusto中针对多行字符串用parse/extract实现非贪婪匹配的问题

Kusto查询:提取C#堆栈跟踪开头到首个分隔符的内容

问题背景

需要匹配msg字段中从开头到首个--- End of或 at的多行内容,处理杂乱的C#异步堆栈跟踪数据,以下是针对两个技术疑问的解答:

疑问1:能否在extract()函数中指定等效于parse kind=regex flags=Us的参数实现非贪婪匹配?

可以。extract()函数支持通过regex_flags参数设置正则标志,其中U对应非贪婪模式,s对应单行模式(让正则中的.匹配换行符),直接用该函数就能一次性提取目标内容:

datatable(msg:string) [
@"Error: ArgumentNullException: foo
  at Microsoft.XXX
  at Microsoft.YYY
  at Microsoft.ZZZ",
@"Error: ArgumentNullException: bar
  --- End of stack trace from previous location ---
  at Microsoft.XXX
  at Microsoft.YYY"
]
| project msg2 = extract(@"^(.*?)(--- End of|  at )", 1, msg, regex_flags=U+s)

疑问2:若只能使用parse运算符,如何完成非贪婪匹配?

可以通过单步parse语句,结合正则分支匹配两个分隔符,同时开启Us标志实现非贪婪匹配,无需链式调用:

datatable(msg:string) [
@"Error: ArgumentNullException: foo
  at Microsoft.XXX
  at Microsoft.YYY
  at Microsoft.ZZZ",
@"Error: ArgumentNullException: bar
  --- End of stack trace from previous location ---
  at Microsoft.XXX
  at Microsoft.YYY"
]
| parse kind=regex flags=Us msg with msg2 @"^(.*?)(--- End of|  at )"
| project msg2

期望输出

Error: ArgumentNullException: foo
Error: ArgumentNullException: bar

内容的提问来源于stack exchange,提问作者redgiant

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 02:15:40