如何通过Azure CLI列出活动Azure Monitor警报并运行资源图查询?
通过Azure CLI列出已触发的活动Azure Monitor警报
当然可以通过Azure CLI运行你提供的Azure资源图查询,同时还有更直接的CLI命令方案,具体如下:
方案一:用Azure CLI执行资源图查询
你可以直接使用az graph query命令运行你的Kusto查询,无需依赖资源图资源管理器:
- 确保已登录Azure CLI并拥有目标订阅的访问权限。
- 直接在命令行执行(注意转义双引号,或用单引号包裹查询内容):
az graph query --query "alertsmanagementresources | where type == 'microsoft.alertsmanagement/alerts' | extend severity = tostring(properties[\"essentials\"][\"severity\"]) | where properties[\"essentials\"][\"monitorCondition\"] in~ ('Fired') | where properties[\"essentials\"][\"startDateTime\"] >= datetime(Tue, 07 Mar 2023 05:49:47 GMT) and properties[\"essentials\"][\"startDateTime\"] <= datetime(Thu, 06 Apr 2023 05:49:47 GMT) | project id,severity,name,essentials = properties[\"essentials\"],subscriptionId | order by todatetime(essentials[\"startDateTime\"]) desc"
如果觉得命令行里写长查询太麻烦,把查询内容保存到一个.kql文件(比如active-alerts.kql),再用以下命令读取执行:
az graph query --file active-alerts.kql
方案二:直接用Azure CLI警报管理命令(更简便)
除了资源图,你还可以用az monitor alert系列命令直接筛选已触发的活动警报,无需编写Kusto查询:
az monitor alert list --state "Fired" --start-time "2023-03-07T05:49:47Z" --end-time "2023-04-06T05:49:47Z"
如果需要自定义输出字段,添加--query参数精简结果:
az monitor alert list --state "Fired" --start-time "2023-03-07T05:49:47Z" --end-time "2023-04-06T05:49:47Z" --query "[].{ID:id, Severity:properties.essentials.severity, Name:name, StartTime:properties.essentials.startDateTime, Subscription:subscriptionId}" --output table
内容的提问来源于stack exchange,提问作者Joel
相关产品推荐
相关产品推荐

