You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure门户筛选组织所有用户发起的活动日志(排除平台操作)

解决Azure活动日志筛选特定域名用户操作的问题

我碰到过好几个用户问这个问题——Azure门户自带的日志筛选确实不支持通配符批量匹配域名,没法直接用*@mycompany.com筛选所有内部用户操作,同时排除平台发起的动作。不过咱们有几个实用的方案能解决,给你详细说说:

方法一:Azure Monitor日志查询(最灵活推荐)

这是功能最强大的方式,前提是你已经把Azure Activity Log导出到了Log Analytics工作区(如果还没配置,去门户的「Activity Log」→「导出设置」,选择要关联的Log Analytics工作区即可)。

进入Log Analytics工作区的「日志」界面,用Kusto查询语言就能精准筛选:

AzureActivity
// 筛选所有来自mycompany.com域名的发起者
| where Caller endswith "@mycompany.com"
// 排除Azure Policy相关操作
| where OperationNameValue !startswith "Microsoft.Authorization/policies/"
// 排除备份管理相关操作
| where OperationNameValue !startswith "Microsoft.RecoveryServices/"
// 可以继续添加更多要排除的平台操作命名空间,比如Azure Automation:
// | where OperationNameValue !startswith "Microsoft.Automation/"
// 展示关键字段
| project TimeGenerated, Caller, OperationName, ResourceGroup, ResourceId

你可以根据实际需求调整排除的操作命名空间,或者添加更多筛选条件(比如按时间范围、资源组等)。

方法二:Azure CLI/PowerShell脚本批量筛选

如果不想用Log Analytics,也可以直接用脚本拉取日志并筛选,适合临时查询或者自动化场景:

PowerShell示例:

# 获取最近7天的活动日志,筛选内部用户并排除平台操作
Get-AzActivityLog -StartTime (Get-Date).AddDays(-7) | 
Where-Object { 
    $_.Caller -like "*@mycompany.com" -and 
    !$_.OperationName.Value.StartsWith("Microsoft.Authorization/policies/") -and
    !$_.OperationName.Value.StartsWith("Microsoft.RecoveryServices/")
} |
Select-Object EventTimestamp, Caller, OperationName, ResourceGroupName, ResourceId

如果需要导出结果到CSV,在最后加上 | Export-Csv -Path "C:\AzureUserActions.csv" -NoTypeInformation 即可。

Azure CLI示例:

# 获取最近7天的活动日志,筛选内部用户并排除平台操作
az monitor activity-log list --start-time $(date -d "-7 days" +%Y-%m-%dT%H:%M:%SZ) |
jq '.[] | select(.caller | endswith("@mycompany.com")) | select(.operationName.value | startswith("Microsoft.Authorization/policies/") | not) | select(.operationName.value | startswith("Microsoft.RecoveryServices/") | not) | {Time: .eventTimestamp, Caller: .caller, Operation: .operationName.localizedValue, ResourceGroup: .resourceGroupName}'

需要提前安装jq来处理JSON输出。

方法三:自定义监控仪表板/警报(长期监控需求)

如果需要长期关注内部用户的操作,基于方法一的Kusto查询,你可以:

  • 在Log Analytics里创建自定义仪表板,可视化展示内部用户的操作趋势、高频操作等;
  • 设置日志警报,当内部用户执行特定操作(或排除平台操作后的所有操作)时触发通知,比如邮件、Teams消息等。

内容的提问来源于stack exchange,提问作者Sakaldeep Yadav

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 23:02:30