You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于ProcessAccount生成RemoteUrl二进制标识的Kusto查询需求

解决Kusto中基于ProcessAccount生成RemoteUrl标识列的问题

需求说明

需基于ProcessAccount数组字段生成RemoteUrl布尔列:

  • 当ProcessAccount仅包含c、r、n(或其任意组合,不区分大小写)时,RemoteUrl为True
  • 若包含其他任何元素,则为False

修正后的Kusto查询

使用array_all函数遍历数组元素,验证所有元素是否属于允许集合:

let allowedAccounts = dynamic(["c", "r", "n"]);
DeviceNetworkEvents
| project TimeGenerated, DeviceName, ProcessAccount
| extend RemoteUrl = array_all(ProcessAccount, x => x in~ allowedAccounts)

或者使用set_difference计算差集,判断是否存在非允许元素:

let allowedAccounts = dynamic(["c", "r", "n"]);
DeviceNetworkEvents
| project TimeGenerated, DeviceName, ProcessAccount
| extend RemoteUrl = array_length(set_difference(ProcessAccount, allowedAccounts, ignore_case=true)) == 0

逻辑说明

  • array_all:遍历ProcessAccount的每个元素,检查是否都匹配允许集合(in~表示不区分大小写)
  • set_difference:计算ProcessAccount与允许集合的差集,若差集长度为0,说明所有元素都在允许范围内

验证结果

针对输入表执行上述查询后,将得到预期输出:

TimeGeneratedDeviceNameProcessAccountRemoteUrl
2023-01-01device1["a","c","I","n"]FALSE
2023-01-01device2["c","n","r"]TRUE
2023-01-01device3["n"]TRUE
2023-01-01device4["r","n"]TRUE
2023-01-01device5["s","c","n","r"]FALSE

内容的提问来源于stack exchange,提问作者user17243359

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 17:43:02