You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在KQL中从TargetResources投影嵌套的id和userPrincipalName字段

解决KQL从AuditLogs的TargetResources提取字段的问题

修正后的查询

AuditLogs
| where ActivityDisplayName contains "Update user" 
  and InitiatedBy.user.userPrincipalName == "Testuser"
| mv-expand TargetResources
| where TargetResources.id == "xxxxxxxx"
| project 
    ActivityDateTime,
    TargetUserId = TargetResources.id,
    TargetUserUPN = TargetResources.userPrincipalName,
    ActivityDisplayName

关键步骤说明

  • mv-expand TargetResources:TargetResources是动态数组类型,直接访问内部字段会失败。mv-expand会把数组拆分为多条独立记录,每条对应数组里的一个元素,这样就能直接读取元素内的id和userPrincipalName字段。
  • 精准匹配过滤:原查询用字符串contains匹配不够严谨,展开后直接用TargetResources.id == "xxxxxxxx"精准定位目标资源;发起用户InitiatedBy是嵌套结构,用InitiatedBy.user.userPrincipalName直接匹配用户UPN更准确。
  • project投影字段:用project指定要输出的字段,还可以给字段重命名(比如TargetUserId),让结果更直观易读。

补充提示

如果TargetResources数组包含多个元素,mv-expand会生成多条对应记录。要是想保留原数组结构同时提取字段,可以用parse_json结合array_iff或bag_extract,但对新手来说mv-expand是最容易上手的方式。

内容的提问来源于stack exchange,提问作者avinash

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 04:45:39