如何使用Azure Resource Graph获取Azure VM最后重启时间
获取Azure虚拟机最后重启/关机日期的Azure Resource Graph查询
你可以通过查询Azure活动日志(映射到Resource Graph的azureactivity表)来获取VM的最后重启或关机时间,以下是具体的Kusto查询示例:
1. 获取最后重启时间
筛选成功执行的VM重启操作,按资源组和VM名称分组取最新事件时间:
azureactivity | where OperationNameValue == "Microsoft.Compute/virtualMachines/restart/action" | where StatusValue == "Succeeded" | project ResourceGroup, Resource, EventSubmissionTimestamp | summarize LastRestartTime = max(EventSubmissionTimestamp) by ResourceGroup, Resource
2. 获取最后关机时间
关机操作包含powerOff(关机保留资源)和deallocate(关机释放资源)两种,以下查询覆盖这两种场景:
azureactivity | where OperationNameValue in ("Microsoft.Compute/virtualMachines/powerOff/action", "Microsoft.Compute/virtualMachines/deallocate/action") | where StatusValue == "Succeeded" | project ResourceGroup, Resource, EventSubmissionTimestamp | summarize LastShutdownTime = max(EventSubmissionTimestamp) by ResourceGroup, Resource
3. 合并查询:同时显示重启和关机时间
通过关联查询,一次性展示VM的最后重启、关机时间:
let restartEvents = azureactivity | where OperationNameValue == "Microsoft.Compute/virtualMachines/restart/action" | where StatusValue == "Succeeded" | project ResourceGroup, Resource, LastRestartTime = EventSubmissionTimestamp; let shutdownEvents = azureactivity | where OperationNameValue in ("Microsoft.Compute/virtualMachines/powerOff/action", "Microsoft.Compute/virtualMachines/deallocate/action") | where StatusValue == "Succeeded" | project ResourceGroup, Resource, LastShutdownTime = EventSubmissionTimestamp; restartEvents | fullouter join shutdownEvents on ResourceGroup, Resource | project ResourceGroup, Resource, LastRestartTime, LastShutdownTime
注意事项
- 活动日志默认仅保留90天,因此只能查询最近90天内的操作记录
- 如果VM从未执行过重启/关机操作,对应的时间字段会显示为
null - 可添加
| where SubscriptionId == "你的订阅ID"筛选指定订阅内的VM
内容的提问来源于stack exchange,提问作者Mohamed Jalil
相关产品推荐
相关产品推荐

