You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Log-Analytics workspace告警失效,如何通过Data Collection Rules创建CPU、内存、磁盘告警

通过Data Collection Rules创建CPU、内存、磁盘告警

前提条件

  • 已完成Data Collection Rules (DCR)的创建与配置,且目标资源(如虚拟机)已与该DCR关联,确保CPU、内存、磁盘的性能数据已被收集至Log Analytics工作区
  • 持有Monitoring Contributor及以上权限,用于创建和配置告警规则

通用告警创建步骤

  1. 登录Azure门户,进入Monitor服务,依次选择Alerts > Create > Alert rule
  2. 在Scope环节,选择存储DCR数据的Log Analytics工作区,点击Next
  3. 切换到Condition页面,选择Custom log search作为信号类型
  4. 在Search query输入框中,填入对应指标的Kusto查询语句(见下文各指标示例),随后设置告警阈值(如CPU使用率超过90%)、评估周期和检查频率
  5. 点击Next,配置Actions:选择已有的动作组(或新建),设置通知方式(邮件、短信等)
  6. 在Details页面,填写告警规则名称、描述、所属资源组,指定告警严重等级(如S1)
  7. 确认所有配置无误后,点击Create alert rule完成创建

CPU使用率告警查询语句

Perf
| where ObjectName == "Processor" and CounterName == "% Processor Time" and InstanceName == "_Total"
| summarize avg(CounterValue) by Computer, bin(TimeGenerated, 5m)
| where avg_CounterValue > 90  // 根据业务需求调整阈值

内存使用率告警查询语句

Perf
| where ObjectName == "Memory" and CounterName == "% Committed Bytes In Use"
| summarize avg(CounterValue) by Computer, bin(TimeGenerated, 5m)
| where avg_CounterValue > 85  // 根据业务需求调整阈值

磁盘使用率告警查询语句

Perf
| where ObjectName == "LogicalDisk" and CounterName == "% Used Space" and InstanceName != "_Total"
| summarize avg(CounterValue) by Computer, InstanceName, bin(TimeGenerated, 5m)
| where avg_CounterValue > 90  // 根据业务需求调整阈值

关键注意事项

  • 需确保DCR的Data sources中已添加对应性能计数器:选择Performance counters类型,勾选Processor、Memory、LogicalDisk下的目标计数器
  • 可根据监控需求调整查询中的时间窗口(bin(TimeGenerated, 5m))和阈值参数
  • 若需针对特定主机告警,可在查询开头添加| where Computer == "目标主机名称"进行过滤

内容的提问来源于stack exchange,提问作者Winslet vasanthraaj ts

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 12:50:21