You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过KQL查询获取Azure变更跟踪的用户名与文件修改内容

Azure Change Tracking 文件变更查询(含用户名与文件名)

核心说明

ConfigurationChange表本身不直接存储文件修改的用户名和具体内容变更,需通过关联日志或调整逻辑获取相关信息:


1. 关联安全日志获取修改用户名

若你的VM已启用Log Analytics代理并收集Windows安全事件(事件ID 4663/4656),可通过关联SecurityEvent表匹配文件修改操作的用户:

ConfigurationChange
| where ConfigChangeType == "Files"
| extend FileName = Name, FullPath = strcat(FileSystemPath, "\\", Name)
// 关联10分钟时间范围内的文件修改安全事件
| join kind=leftouter (
    SecurityEvent
    | where EventID in ("4663", "4656") // 对应文件访问/修改操作
    | where Activity startswith "%%1537" or Activity startswith "%%1538" // 筛选修改类操作
    | extend FullPath = TargetFileName, Account = strcat(AccountDomain, "\\", AccountName)
    | project TimeGenerated, FullPath, Account
) on $left.TimeGenerated between $right.TimeGenerated - 10m and $right.TimeGenerated + 10m, FullPath
| project Computer, FileName, FullPath, ChangeCategory, PreviousSize, Size, DateModified, FieldsChanged, Account, Attributes
| sort by TimeGenerated asc

2. 文件内容变更的限制说明

Change Tracking仅记录文件元数据变更(如大小、哈希、属性),不会存储具体内容差异。若需追踪内容变更,需额外配置:

  • 对云存储文件启用Azure File Sync版本控制
  • 在VM上部署第三方内容审计工具,将变更日志同步至Log Analytics

3. 原查询优化(明确文件名字段)

若仅需明确展示文件名,可直接调整原查询的字段标注:

ConfigurationChange
| where ConfigChangeType == "Files"
| sort by TimeGenerated asc
| project 
    Computer, 
    FileName = Name, // 明确标注为文件名
    FullFilePath = strcat(FileSystemPath, "\\", Name),
    ChangeCategory, 
    PreviousSize, 
    Size, 
    DateModified, 
    FieldsChanged, 
    FileContentChecksum, 
    Attributes

内容的提问来源于stack exchange,提问作者Srikanth Mannepalli

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 11:07:43