如何在Azure Log Analytics中获取按命名空间过滤、按服务分组的CPU与内存使用率时序图表?
Fixing Your KQL Query for Time-Series CPU/Memory Metrics by Service
Let's break down what's missing in your original query and fix it to get the time-series data you need, plus add memory usage tracking for complete visibility.
Key Issues in the Original Query
- Ambiguous
ServiceName: Your query referencesServiceNamebut doesn't define where it comes from.KubePodInventorydoesn't have a built-inServiceNamefield—you'll need to extract it from your pod's labels (like theapporservicelabel that maps to your Kubernetes service). - Unqualified Time Field: After joining
KubePodInventoryandPerf, there are twoTimeGeneratedfields. You need to explicitly referencePerf.TimeGeneratedto bucket time based on when the metric was actually collected. - Unfiltered Join: Joining without a time range can lead to slow queries and inaccurate data associations. Adding a time filter will speed things up and improve reliability.
Corrected KQL Query (CPU + Memory)
// Define your target namespace and analysis time range let targetNamespace = "your-namespace"; let timeRange = ago(1h); // Adjust to your desired window (e.g., ago(6h), ago(1d)) // Get pod inventory with service name extracted from labels KubePodInventory | where Namespace == targetNamespace | where TimeGenerated >= timeRange // Extract ServiceName from pod labels - update the label key to match your setup | extend ServiceName = tostring(Labels['app']) | extend InstanceName = strcat(ClusterId, '/', ContainerName) // Join with Perf metrics, filtering to only relevant container metrics | join kind=inner ( Perf | where TimeGenerated >= timeRange | where ObjectName == 'K8SContainer' | where CounterName in ('cpuUsageNanoCores', 'memoryRssBytes') ) on InstanceName // Bucket time into 1-minute intervals and aggregate by service | summarize AvgCPUUsageCores = avg(CounterValue) / 1000000000, AvgMemoryUsageGB = avg(CounterValue) / 1024 / 1024 / 1024 by LogTime = bin(Perf.TimeGenerated, 1m), ServiceName, CounterName // Pivot to have CPU and memory as separate columns for easier charting | pivot(CounterName, any(AvgCPUUsageCores), any(AvgMemoryUsageGB)) | project LogTime, ServiceName, AvgCPUUsageCores, AvgMemoryUsageGB | order by LogTime asc
Quick Adjustments for Your Environment
- Service Name Extraction: Replace
Labels['app']with the actual label key your services use (e.g.,Labels['service']orLabels['app.kubernetes.io/name']). You can check your pod labels withKubePodInventory | where Namespace == targetNamespace | project Labelsif you're unsure. - Memory Metric: We use
memoryRssBytesfor resident set size memory usage—swap tomemoryWorkingSetBytesif that's the metric you need instead. - Time Granularity: Change
bin(Perf.TimeGenerated, 1m)to5mor15mif you want coarser time buckets.
Generating the Time-Series Chart
Once you run the corrected query in Azure Monitor Logs:
- Switch to the Chart tab (next to the Table view).
- Select Line chart as the chart type.
- Set the X-axis to
LogTime. - Add
AvgCPUUsageCoresandAvgMemoryUsageGBto the Y-axis. - Use
ServiceNameas the Series to group lines by each service.
This will give you a clear, interactive view of how average CPU and memory usage changes over time for each service in your namespace.
内容的提问来源于stack exchange,提问作者anoopjohn
相关产品推荐
相关产品推荐

