You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kusto查询:无需指定数组索引匹配properties中的目标邮箱

Kusto查询中无需指定数组索引匹配emailReceivers中的邮箱地址

要实现无需指定数组索引匹配emailReceivers数组中的目标邮箱,你可以采用以下两种实用方法:

方法1:使用array_contains函数

直接利用array_contains函数遍历数组,检查是否存在符合条件的元素:

resources
| where type == 'microsoft.insights/actiongroups'
| where properties["enabled"] in~ ('true')
| where array_contains(properties.emailReceivers, dynamic({"emailAddress": "DevSecOps@pato.com"}), false)
| project id,name,resourceGroup,subscriptionId,properties,location
| order by tolower(tostring(name)) asc
  • 第三个参数false表示匹配时不区分大小写,若需严格区分可改为true
  • 函数会自动遍历整个emailReceivers数组,无需指定具体索引

方法2:使用mv-expand展开数组

将数组展开为单独行后过滤,适合需要查看具体匹配接收器的场景:

resources
| where type == 'microsoft.insights/actiongroups'
| where properties["enabled"] in~ ('true')
| mv-expand receiver = properties.emailReceivers
| where receiver.emailAddress == "DevSecOps@pato.com"
| project id,name,resourceGroup,subscriptionId,properties,location
| order by tolower(tostring(name)) asc
| distinct id, name, resourceGroup, subscriptionId, properties, location // 避免同一资源重复出现

展开后每一行对应一个邮箱接收器,过滤完成后通过distinct去重,确保每个资源只出现一次。

补充说明

你之前尝试的[*]无法直接在where条件中生效,因为[*]的作用是提取数组所有元素的指定属性(比如properties.emailReceivers[*].emailAddress会返回所有邮箱地址组成的数组),若要基于这个数组判断是否包含目标值,也可以结合set_has_element函数:

resources
| where type == 'microsoft.insights/actiongroups'
| where properties["enabled"] in~ ('true')
| where set_has_element(properties.emailReceivers[*].emailAddress, "DevSecOps@pato.com")
| project id,name,resourceGroup,subscriptionId,properties,location
| order by tolower(tostring(name)) asc

内容的提问来源于stack exchange,提问作者Heriberto Martinez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 09:40:42