如何用KQL统计每日每小时VM连接数及会话主机在线用户数
按小时统计VM连接数及用户数的KQL实现
你可以通过以下KQL代码实现一天内每小时的VM连接数量统计,以及每小时连接到会话主机的唯一用户数统计:
WVDConnections | where SessionHostName contains "VM" | where State contains "Started" | where TimeGenerated between (ago(1d) and now()) // 统计最近1天的数据,可替换为具体时间段 | summarize 每小时连接数量 = count(), 每小时唯一用户数 = dcount(UserName) by 小时时间段 = bin(TimeGenerated, 1h) | sort by 小时时间段 asc
代码逻辑说明:
- 筛选会话主机名称包含"VM"的连接事件,且仅保留连接发起(
State contains "Started")的记录,确保统计的是新发起的连接 - 通过
bin(TimeGenerated, 1h)将时间按1小时粒度分桶,作为分组统计的维度 - 使用
count()统计每个小时内的总连接数,dcount(UserName)统计该小时内的唯一用户数(自动去重) - 最后按时间升序排列结果,便于查看小时级的趋势
自定义调整:
- 若需要统计指定日期而非最近一天,可将时间筛选条件替换为具体时间段,例如:
| where TimeGenerated between (datetime(2024-05-20 00:00:00) and datetime(2024-05-21 00:00:00)) - 若需统计每小时的活跃连接数(即该小时内处于连接状态的会话数),可基于你原有的关联Started/Completed事件的逻辑,结合小时分桶计算:
WVDConnections | where SessionHostName contains "VM" | extend EventTime = TimeGenerated | summarize StartedTime = minif(EventTime, State contains "Started"), CompletedTime = maxif(EventTime, State contains_cs "Completed") by CorrelationId, SessionHostName, UserName | where StartedTime != datetime(null) // 生成每个连接覆盖的小时区间 | mv-expand 小时时间段 = range(bin(StartedTime, 1h), bin(coalesce(CompletedTime, now()), 1h), 1h) | summarize 每小时活跃连接数 = count_distinct(CorrelationId), 每小时唯一用户数 = dcount(UserName) by 小时时间段 | sort by 小时时间段 asc
内容的提问来源于stack exchange,提问作者TMAC
相关产品推荐
相关产品推荐

