Kusto查询:无需指定数组索引匹配properties中的目标邮箱
Kusto查询中无需指定数组索引匹配emailReceivers中的邮箱地址
要实现无需指定数组索引匹配emailReceivers数组中的目标邮箱,你可以采用以下两种实用方法:
方法1:使用array_contains函数
直接利用array_contains函数遍历数组,检查是否存在符合条件的元素:
resources | where type == 'microsoft.insights/actiongroups' | where properties["enabled"] in~ ('true') | where array_contains(properties.emailReceivers, dynamic({"emailAddress": "DevSecOps@pato.com"}), false) | project id,name,resourceGroup,subscriptionId,properties,location | order by tolower(tostring(name)) asc
- 第三个参数
false表示匹配时不区分大小写,若需严格区分可改为true - 函数会自动遍历整个
emailReceivers数组,无需指定具体索引
方法2:使用mv-expand展开数组
将数组展开为单独行后过滤,适合需要查看具体匹配接收器的场景:
resources | where type == 'microsoft.insights/actiongroups' | where properties["enabled"] in~ ('true') | mv-expand receiver = properties.emailReceivers | where receiver.emailAddress == "DevSecOps@pato.com" | project id,name,resourceGroup,subscriptionId,properties,location | order by tolower(tostring(name)) asc | distinct id, name, resourceGroup, subscriptionId, properties, location // 避免同一资源重复出现
展开后每一行对应一个邮箱接收器,过滤完成后通过distinct去重,确保每个资源只出现一次。
补充说明
你之前尝试的[*]无法直接在where条件中生效,因为[*]的作用是提取数组所有元素的指定属性(比如properties.emailReceivers[*].emailAddress会返回所有邮箱地址组成的数组),若要基于这个数组判断是否包含目标值,也可以结合set_has_element函数:
resources | where type == 'microsoft.insights/actiongroups' | where properties["enabled"] in~ ('true') | where set_has_element(properties.emailReceivers[*].emailAddress, "DevSecOps@pato.com") | project id,name,resourceGroup,subscriptionId,properties,location | order by tolower(tostring(name)) asc
内容的提问来源于stack exchange,提问作者Heriberto Martinez
相关产品推荐
相关产品推荐

