You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

KQL:如何用通配符或其他方式匹配两个字符串数组的域名/关键词并对比

解决方案:基于前缀匹配过滤字符串数组

原查询使用set_difference只能做精确字符串匹配,所以无法识别test2.com/1234/包含test2.com域名的情况。要实现域名/关键词的前缀(或包含)匹配过滤,可借助Kusto的字符串匹配函数结合数组展开、过滤逻辑处理,具体如下:

完整查询代码

let url1 = dynamic(["test2.com","test4.com"]);
let url2 = dynamic(["test.com", "test2.com/1234/", "test3.com"]);
url2
| mv-expand item = url2
| where not(url1 has_prefix item)
| summarize result = make_set(item)

步骤说明

  • mv-expand item = url2:将url2数组拆分为单行单元素的结构,便于逐个检查每个字符串。
  • where not(url1 has_prefix item):利用has_prefix函数判断当前字符串是否以url1中的任意元素为前缀,通过not取反,保留不匹配的项。如果需要的是包含匹配(域名出现在字符串任意位置),可将has_prefix替换为contains。
  • summarize result = make_set(item):将过滤后的元素重新聚合为数组,得到最终结果。

执行上述查询后,输出的result即为预期的["test.com","test3.com"]。

内容的提问来源于stack exchange,提问作者Gary

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 19:35:16