如何用优雅方式在Kusto查询中排除含指定关键词的资源?
用Kusto批量排除含指定关键词的资源类型
你可以通过**动态数组+array_has_any()**的方式,批量替代重复的!contains语句,写法更简洁且易于维护:
优化后的查询代码
// Find_Untagged_Resources resources | join kind=inner ( resourcecontainers | where type == 'microsoft.resources/subscriptions' | project subscriptionId, subscriptionName = name) on subscriptionId // Use this for testing //| where type =~ 'Microsoft.Compute/virtualMachines' or type =~ "microsoft.sql/servers/databases" | where name != "master" // 批量排除含指定关键词的资源类型 | where not array_has_any(dynamic(["alert", "extensions"]), x => type contains x) | where isnull(tags.application) or isnull(tags.boundary) or isnull(tags.costCenter) or isnull(tags.createdBy) or isnull(tags.customerCode) or isnull(tags.env) or isnull(tags.managedBy) or isnull(tags.ownedBy) | project subscriptionName, resourceGroup, name, type,location,tags.application,tags.boundary,tags.costCenter,tags.createdBy,tags.customerCode,tags.env,tags.managedBy,tags.ownedBy,tags.shared,tags.version | order by ['resourceGroup'] asc
关键逻辑说明
- 用
dynamic(["alert", "extensions"])定义要排除的关键词列表,后续新增关键词直接在数组里添加即可 array_has_any(数组, 匹配逻辑)会检查type是否包含数组中的任意一个关键词- 前面加
not,就实现了“资源类型不包含任何指定关键词”的逻辑,完全替代原来多次重复的!contains语句
补充:整词匹配场景
如果你的关键词是完整单词(不是子串),可以用更高效的!has_any()写法(区分大小写),不区分大小写则用!has_any~():
| where type !has_any("alert", "extensions")
内容的提问来源于stack exchange,提问作者Francesco Mantovani
相关产品推荐
相关产品推荐

