如何解决Application Insights告警Kusto查询周六时段误发周日通知问题
Application Insights告警误触发(周日也收到通知)的排查与修复
你的查询目前仅过滤了timestamp属于周六7:00-13:00的请求,但如果告警规则在周日运行,ago(24h)的时间范围会包含周六的记录,查询依然会返回结果并触发告警。核心问题是你既没限制告警的运行时间,也没在查询里校验当前时间是否处于目标时段。
方案一:修改Kusto查询,增加当前时间校验
在查询中同时过滤now()处于周六7:00-13:00,确保只有在这个时段内运行查询才会返回符合条件的记录:
requests | extend Customer= trim_end('/', tostring(split(customDimensions.source, '//')[1])) | extend alarmOK=iif(datetime_diff('minute', now(), timestamp) > 20, 1, 0) | extend issaturday=iif(dayofweek(timestamp) == 6d, 1, 0) | extend workinghour = hourofday(timestamp) // 校验当前时间是否在周六目标时段内 | extend current_is_saturday = iif(dayofweek(now()) == 6d, 1, 0) | extend current_workinghour = hourofday(now()) | extend current_in_window = iif(current_workinghour >=7 and current_workinghour <13, 1, 0) | extend alarmmessage = "alert message" | where timestamp > ago(24h) and Customer == "mycustomer" | where issaturday == 1 | where workinghour >=7 and workinghour <13 // 仅当当前时间在目标窗口时才返回结果 | where current_is_saturday ==1 and current_in_window ==1 | top 1 by timestamp desc
方案二:配置告警规则的运行时间窗口(推荐)
直接在Application Insights告警规则的调度设置里,限定仅在周六7:00-13:00运行查询:
- 进入告警规则编辑页面,找到「调度」选项
- 设置运行频率为你需要的间隔(比如5分钟)
- 开启「设置时间窗口」,选择每周六,时间范围设为7:00-13:00
- 保存配置
这样无需修改查询,告警也只会在指定时段触发,不会在周日运行。
内容的提问来源于stack exchange,提问作者loki
相关产品推荐
相关产品推荐

