You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Kusto中将字符串格式的日期列转换为日期类型

解决Kusto字符串日期转datetime类型的问题

你需要将提取的字符串日期转换为datetime类型,才能和ago()这类日期函数的结果进行比较或使用日期相关函数。Kusto提供两种常用转换方式:

1. 自动识别格式转换(适用于标准日期字符串)

如果你的日期字符串是Kusto默认支持的格式(比如yyyy-MM-ddTHH:mm:ss.fff这类ISO格式),直接用todatetime()函数转换即可:

UserLogs 
| project DateStr=substring(RawData, 0, 22), RawData
| project Date=todatetime(DateStr), RawData=substring(RawData, 24, 150)
| where RawData has "Login" and isnotnull(Date)  // 过滤转换失败的无效记录
| where Date > ago(15m)

2. 指定格式转换(适用于非标准日期字符串)

如果日期字符串格式特殊,Kusto无法自动识别,就用parse_datetime()函数并指定格式字符串。比如假设你的日期格式是yyyy-MM-dd HH:mm:ss.fff,写法如下:

UserLogs 
| project DateStr=substring(RawData, 0, 22), RawData
| project Date=parse_datetime(DateStr, "yyyy-MM-dd HH:mm:ss.fff"), RawData=substring(RawData, 24, 150)
| where RawData has "Login" and isnotnull(Date)
| where Date > ago(15m)

补充说明

  • 转换后的Date列是标准datetime类型,支持所有Kusto日期函数(如startofday()、datetime_diff()等)和日期比较操作。
  • 添加isnotnull(Date)可以过滤掉转换失败的无效日期记录,避免干扰后续查询逻辑。

内容的提问来源于stack exchange,提问作者Aviator

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 12:53:11