如何基于Azure Monitor通用告警通知获取异常列表及所需API?
问题描述
收到如下Azure Monitor智能检测告警:
{ "schemaId":"azureMonitorCommonAlertSchema", "data":{ "essentials":{ "alertId":"/subscriptions//providers/Microsoft.AlertsManagement/alerts/", "alertRule":"Exception Anomalies - ", "severity":"Sev3", "signalType":"Log", "monitorCondition":"Fired", "monitoringService":"SmartDetector", "alertTargetIDs":[ "/subscriptions//resourcegroups//providers/microsoft.insights/components/" ], "configurationItems":[ "CHANGEDNAME" ], "originAlertId":"CHANGEDGUID", "firedDateTime":"2022-12-29T04:47:14.5840789Z", "description":"Exception Anomalies notifies you of an unusual rise in the rate of exceptions thrown by your app.", "essentialsVersion":"1.0", "alertContextVersion":"1.0" }, "alertContext":{ "DetectionSummary":"90 ‘System.Net.Sockets.SocketException’ exceptions (the average volume of the exception in previous 7 days was 0)", "FormattedOccurrenceTime":"2022-12-28T23:59:59Z", "DetectedValue":"90", "CustomProperty":"0 (over previous 7 days)", "PresentationInsightEventRequest":"/", "SmartDetectorId":"ExceptionVolumeChangedDetector", "SmartDetectorName":"Exception Volume Changed Detector", "AnalysisTimestamp":"2022-12-29T04:47:14.5840789Z" }, "customProperties":null } }
希望无需进入Application Insights界面,直接通过API获取该告警对应的异常列表,需使用什么API?
解决方案
你需要使用Azure Monitor Log Analytics 查询 API(对应Application Insights的日志查询接口),具体操作步骤如下:
1. 提取目标资源ID
从告警的data.essentials.alertTargetIDs字段中,获取Application Insights资源的完整ID(格式为/subscriptions/{subscriptionId}/resourcegroups/{resourceGroupName}/providers/microsoft.insights/components/{componentName})。
2. 构造Kusto查询语句
结合告警上下文的信息,编写针对exceptions日志表的查询语句,精准过滤目标异常:
- 时间范围:以
alertContext.FormattedOccurrenceTime为基准,取前后1小时(可根据实际场景调整)的时间区间 - 异常类型:从
alertContext.DetectionSummary中提取异常类型(示例中为System.Net.Sockets.SocketException)
示例查询语句:
exceptions | where timestamp between(datetime(2022-12-28T22:59:59Z) .. datetime(2022-12-29T00:59:59Z)) | where type == "System.Net.Sockets.SocketException" | project timestamp, type, message, operation_Id, details, user_Id
3. 调用API获取结果
发起POST请求调用Logs - Query API:
- 请求URL:
POST https://management.azure.com/{resourceId}/query?api-version=2021-05-01 - 请求体示例:
{ "query": "exceptions | where timestamp between(datetime(2022-12-28T22:59:59Z) .. datetime(2022-12-29T00:59:59Z)) | where type == \"System.Net.Sockets.SocketException\" | project timestamp, type, message" }
- 认证要求:需通过Azure AD获取访问令牌,可使用服务主体(Service Principal)或用户身份完成认证。
关键说明
- 该API直接查询Application Insights存储的原始异常日志,返回结果与界面中“View detected exceptions”展示的内容完全一致。
- 可根据告警中的
firedDateTime和FormattedOccurrenceTime动态调整查询的时间范围,确保覆盖异常发生的完整时段。
内容的提问来源于stack exchange,提问作者really
相关产品推荐
相关产品推荐

