You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Kusto scan()算子确定会话的开始和结束时间

Kusto会话分组:基于连续相同reason_code生成会话起止时间

我有一张存储连续遥测数据的表,仅包含Timestamp(表示事件开始时间)和reason_code字段。需要获取每个会话的开始与结束时间戳:

  • 会话定义:reason_code相同的连续记录集合
  • 结束时间戳:下一个不同reason_code事件的时间戳

源数据

Timestampreason_code
2023-02-28 01:07:01.98400004
2023-02-28 02:07:07.53300004
2023-02-28 03:07:13.95100004
2023-02-28 03:58:52.51900000
2023-02-28 04:58:57.98900000
2023-02-28 05:35:34.9820000101
2023-02-28 05:35:44.99300001
2023-02-28 05:38:43.57600000
2023-02-28 05:55:24.17500000
2023-02-28 06:22:23.6230000101
2023-02-28 06:22:33.63400004
2023-02-28 06:28:48.0060000102
2023-02-28 06:51:06.2370000101
2023-02-28 06:51:10.24200004
2023-02-28 06:55:28.49600004
2023-02-28 06:57:56.6280000102
2023-02-28 07:38:30.8380000101

期望输出

start_tsend_tsreason_codesession
2023-02-28 01:07:01.98400002023-02-28 03:58:52.519000041
2023-02-28 03:58:52.51900002023-02-28 05:35:34.982000002
2023-02-28 05:35:34.98200002023-02-28 05:35:44.99300001013
2023-02-28 05:35:44.99300002023-02-28 05:38:43.576000014
2023-02-28 05:38:43.57600002023-02-28 06:22:23.623000005
2023-02-28 06:22:23.62300002023-02-28 06:22:33.63400001016
2023-02-28 06:22:33.63400002023-02-28 06:28:48.006000047
2023-02-28 06:28:48.00600002023-02-28 06:51:06.23700001028
2023-02-28 06:51:06.23700002023-02-28 06:51:10.24200001019
2023-02-28 06:51:10.24200002023-02-28 06:57:56.6280000410
2023-02-28 06:57:56.62800002023-02-28 07:38:30.838000010211
2023-02-28 07:38:30.838000010112

当前实现与优化需求

我认为scan()算子适合解决这个问题,但还没完全掌握其用法,当前实现代码如下:

T
| scan with 
(
    step s1 output=all: isempty(s1.reason_code) or s1.reason_code != reason_code;
)
| extend EndTs=next(Timestamp)
| project-rename StartTs=Timestamp

这个方案不够最优,希望找到**仅依赖scan()**的更简洁实现方式,求建议。


内容的提问来源于stack exchange,提问作者DocZerø

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 04:37:08