如何使用KQL parse拆分含IP与端口的换行分隔长字符串
KQL:拆分换行分隔的IP地址与端口字符串为独立条目
需求:将一段以换行分隔的IP地址:端口格式长字符串,拆分为每行对应独立的IP地址和端口条目,目标输出示例:
| IP address | Port |
|---|---|
| 237.148.51.168 | 445 |
| 208.250.127.105 | 63 |
| 154.133.47.172 | 0 |
问题描述
当前使用的KQL代码无法识别换行作为分隔符,仅能拆分第一组IP与端口,其余所有内容被混入Port字段,错误代码如下:
datatable(randomIpAddress:string)[`237.148.51.168:445 208.250.127.105:63 154.133.47.172:0 246.249.197.54:4673 29.219.118.47:80 63.65.217.14:80 38.190.162.134:10 128.109.247.102:383 241.154.59.142:445 29.12.140.178:0`] | parse ipAddressList with ipAddress:string ':' port:string | project-away ipAddressList
正确实现方法
需要先将长字符串按换行符拆分为单个IP:Port条目,再展开为多行后拆分IP与端口,完整代码如下:
datatable(randomIpAddress:string)[`237.148.51.168:445 208.250.127.105:63 154.133.47.172:0 246.249.197.54:4673 29.219.118.47:80 63.65.217.14:80 38.190.162.134:10 128.109.247.102:383 241.154.59.142:445 29.12.140.178:0`] // 按换行符拆分长字符串为数组 | extend ip_port_entries = split(randomIpAddress, '\n') // 展开数组为单独行 | mv-expand ip_port_entries to typeof(string) // 过滤可能的空行(如果字符串首尾有换行) | where ip_port_entries != "" // 拆分每个条目为IP和端口 | parse ip_port_entries with ipAddress:string ':' port:string // 清理不需要的列 | project ipAddress, port
代码说明
split(randomIpAddress, '\n'):将原始长字符串按换行符\n拆分为包含多个IP:Port字符串的数组mv-expand ip_port_entries:将数组中的每个元素展开为单独的数据行where ip_port_entries != "":过滤拆分后可能出现的空行(避免原始字符串首尾或中间有空行导致无效条目)parse ip_port_entries with ...:对每行的IP:Port字符串拆分出IP地址和端口字段project ipAddress, port:保留需要的字段,移除临时列
内容的提问来源于stack exchange,提问作者ajnabz
相关产品推荐
相关产品推荐

