You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法创建适用于Azure指标警报的有效KQL自定义日志查询

问题解决:Azure Monitor指标警报KQL查询报错修复

问题描述

使用以下KQL查询作为Azure Monitor指标警报时触发错误:

Perf
| where TimeGenerated > ago(60m)
| where (ObjectName == "Processor")
| summarize AggregatedValue = avg(CounterValue) by Computer , _ResourceId
| where AggregatedValue < 100
| project Computer, AggregatedValue

错误信息:

针对指标警报类型,搜索查询需包含'AggregatedValue'和'bin(TimeGenerated, [roundTo])'

注:该查询在Azure Monitor日志中可正常运行。

原因分析

指标警报的运行逻辑要求查询必须按固定时间粒度分箱(通过bin(TimeGenerated, <时间间隔>)实现),因为它需要基于周期性的时间窗口持续评估聚合指标。原查询仅按Computer和_ResourceId聚合,缺少时间维度的分箱逻辑,不符合指标警报的要求。

修改后的查询

Perf
| where TimeGenerated > ago(60m)
| where ObjectName == "Processor"
| summarize AggregatedValue = avg(CounterValue) by Computer, _ResourceId, bin(TimeGenerated, 5m) // 添加时间分箱,5m可根据警报规则调整
| where AggregatedValue < 100
| project Computer, AggregatedValue, TimeGenerated

关键修改说明

  • 在summarize的by子句中加入bin(TimeGenerated, <时间间隔>),时间间隔需与你的指标警报规则中的评估频率和窗口大小匹配(比如评估频率设为5分钟就用5m,设为15分钟则用15m)。
  • 保留AggregatedValue字段(原查询已包含,无需额外修改),这是指标警报识别聚合值的必填字段。

内容的提问来源于stack exchange,提问作者praveen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 05:15:39