You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用KQL parse拆分含IP与端口的换行分隔长字符串

KQL:拆分换行分隔的IP地址与端口字符串为独立条目

需求:将一段以换行分隔的IP地址:端口格式长字符串,拆分为每行对应独立的IP地址和端口条目,目标输出示例:

IP addressPort
237.148.51.168445
208.250.127.10563
154.133.47.1720

问题描述

当前使用的KQL代码无法识别换行作为分隔符,仅能拆分第一组IP与端口,其余所有内容被混入Port字段,错误代码如下:

datatable(randomIpAddress:string)[`237.148.51.168:445
208.250.127.105:63
154.133.47.172:0
246.249.197.54:4673
29.219.118.47:80
63.65.217.14:80
38.190.162.134:10
128.109.247.102:383
241.154.59.142:445
29.12.140.178:0`]
| parse ipAddressList with ipAddress:string ':' port:string 
| project-away ipAddressList

正确实现方法

需要先将长字符串按换行符拆分为单个IP:Port条目,再展开为多行后拆分IP与端口,完整代码如下:

datatable(randomIpAddress:string)[`237.148.51.168:445
208.250.127.105:63
154.133.47.172:0
246.249.197.54:4673
29.219.118.47:80
63.65.217.14:80
38.190.162.134:10
128.109.247.102:383
241.154.59.142:445
29.12.140.178:0`]
// 按换行符拆分长字符串为数组
| extend ip_port_entries = split(randomIpAddress, '\n')
// 展开数组为单独行
| mv-expand ip_port_entries to typeof(string)
// 过滤可能的空行(如果字符串首尾有换行)
| where ip_port_entries != ""
// 拆分每个条目为IP和端口
| parse ip_port_entries with ipAddress:string ':' port:string
// 清理不需要的列
| project ipAddress, port

代码说明

  1. split(randomIpAddress, '\n'):将原始长字符串按换行符\n拆分为包含多个IP:Port字符串的数组
  2. mv-expand ip_port_entries:将数组中的每个元素展开为单独的数据行
  3. where ip_port_entries != "":过滤拆分后可能出现的空行(避免原始字符串首尾或中间有空行导致无效条目)
  4. parse ip_port_entries with ...:对每行的IP:Port字符串拆分出IP地址和端口字段
  5. project ipAddress, port:保留需要的字段,移除临时列

内容的提问来源于stack exchange,提问作者ajnabz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 10:00:13