You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何基于Azure Monitor通用告警通知获取异常列表及所需API?

问题描述

收到如下Azure Monitor智能检测告警:

{
   "schemaId":"azureMonitorCommonAlertSchema",
   "data":{
      "essentials":{
         "alertId":"/subscriptions//providers/Microsoft.AlertsManagement/alerts/",
         "alertRule":"Exception Anomalies - ",
         "severity":"Sev3",
         "signalType":"Log",
         "monitorCondition":"Fired",
         "monitoringService":"SmartDetector",
         "alertTargetIDs":[
            "/subscriptions//resourcegroups//providers/microsoft.insights/components/"
         ],
         "configurationItems":[
            "CHANGEDNAME"
         ],
         "originAlertId":"CHANGEDGUID",
         "firedDateTime":"2022-12-29T04:47:14.5840789Z",
         "description":"Exception Anomalies notifies you of an unusual rise in the rate of exceptions thrown by your app.",
         "essentialsVersion":"1.0",
         "alertContextVersion":"1.0"
      },
      "alertContext":{
         "DetectionSummary":"90 ‘System.Net.Sockets.SocketException’ exceptions (the average volume of the exception in previous 7 days was 0)",
         "FormattedOccurrenceTime":"2022-12-28T23:59:59Z",
         "DetectedValue":"90",
         "CustomProperty":"0 (over previous 7 days)",
         "PresentationInsightEventRequest":"/",
         "SmartDetectorId":"ExceptionVolumeChangedDetector",
         "SmartDetectorName":"Exception Volume Changed Detector",
         "AnalysisTimestamp":"2022-12-29T04:47:14.5840789Z"
      },
      "customProperties":null
   }
}

希望无需进入Application Insights界面,直接通过API获取该告警对应的异常列表,需使用什么API?

解决方案

你需要使用Azure Monitor Log Analytics 查询 API(对应Application Insights的日志查询接口),具体操作步骤如下:

1. 提取目标资源ID

从告警的data.essentials.alertTargetIDs字段中,获取Application Insights资源的完整ID(格式为/subscriptions/{subscriptionId}/resourcegroups/{resourceGroupName}/providers/microsoft.insights/components/{componentName})。

2. 构造Kusto查询语句

结合告警上下文的信息,编写针对exceptions日志表的查询语句,精准过滤目标异常:

  • 时间范围:以alertContext.FormattedOccurrenceTime为基准,取前后1小时(可根据实际场景调整)的时间区间
  • 异常类型:从alertContext.DetectionSummary中提取异常类型(示例中为System.Net.Sockets.SocketException)

示例查询语句:

exceptions
| where timestamp between(datetime(2022-12-28T22:59:59Z) .. datetime(2022-12-29T00:59:59Z))
| where type == "System.Net.Sockets.SocketException"
| project timestamp, type, message, operation_Id, details, user_Id

3. 调用API获取结果

发起POST请求调用Logs - Query API:

  • 请求URL:POST https://management.azure.com/{resourceId}/query?api-version=2021-05-01
  • 请求体示例:
{
    "query": "exceptions | where timestamp between(datetime(2022-12-28T22:59:59Z) .. datetime(2022-12-29T00:59:59Z)) | where type == \"System.Net.Sockets.SocketException\" | project timestamp, type, message"
}
  • 认证要求:需通过Azure AD获取访问令牌,可使用服务主体(Service Principal)或用户身份完成认证。

关键说明

  • 该API直接查询Application Insights存储的原始异常日志,返回结果与界面中“View detected exceptions”展示的内容完全一致。
  • 可根据告警中的firedDateTime和FormattedOccurrenceTime动态调整查询的时间范围,确保覆盖异常发生的完整时段。

内容的提问来源于stack exchange,提问作者really

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 10:30:44