使用current_principal_is_member_of遇语法错误,求参数格式修正方案
问题
执行以下KQL查询时遇到语法错误:
datatable (Brand:string, Country:string, Store:string) [ 'brand1', 'SE', 'Store1', 'brand2', 'SE', 'Store2' ] | distinct Brand, Country, Store | order by Brand, Country, Store | extend _groupToCheck = strcat(Brand, "-",tolower(Country), "-store-", tolower(Store)) | extend _isValidStore = current_principal_is_member_of(_groupToCheck)
错误信息:
current_principal_is_member_of: argument #1 must be a constant string or constant dynamic array of string literals with up to 64 elements
期望得到的结果格式:
Brand, Country, Store, isValidStore Brand1 SE Store1 1 Brand2 SE Store2 0
解决方案
current_principal_is_member_of()函数的参数只能是常量字符串或常量动态数组,无法直接引用查询中的列值(比如_groupToCheck)。要实现需求,需要换用evaluate current_principal_member_of()获取当前用户的所有所属组,再通过关联匹配判断:
datatable (Brand:string, Country:string, Store:string) [ 'brand1', 'SE', 'Store1', 'brand2', 'SE', 'Store2' ] | distinct Brand, Country, Store | order by Brand, Country, Store | extend _groupToCheck = strcat(Brand, "-", tolower(Country), "-store-", tolower(Store)) // 获取当前用户的所有AD组列表 | join kind=leftouter ( evaluate current_principal_member_of() | extend GroupName = tolower(Group) // 统一小写消除大小写匹配问题 ) on $left._groupToCheck == $right.GroupName // 标记是否为有效门店:匹配到组则为1,否则为0 | extend isValidStore = iif(isnotempty(Group), 1, 0) // 保留目标输出列 | project Brand, Country, Store, isValidStore
逻辑说明:
evaluate current_principal_member_of()会返回当前用户所属的所有AD安全组/分发组,每行对应一个组- 通过
leftouterjoin将原始数据中的门店组标识(_groupToCheck)与用户的组列表关联 - 用
iif()判断是否存在匹配的组,生成isValidStore列(1表示用户属于该组,0表示不属于)
内容的提问来源于stack exchange,提问作者Matt Douhan
相关产品推荐
相关产品推荐

