You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在JSON数组上执行mv-apply后如何保留空结果行?

Azure AuditLogs查询:保留无AppId的记录

问题背景

需要查询Azure AuditLogs中30天内"Add application"操作记录:

  • 最初的Query 1依赖modifiedProperties[0]索引获取AppId,当AppId不在该位置时会导致字段为空(比如App2)。
  • 优化后的Query 2使用mv-apply匹配displayName == "AppId"的项,但因为默认是内连接逻辑,没有匹配项的行(如App2)会被过滤掉。

修改后的查询(Query 3)

AuditLogs
| where TimeGenerated > ago(30d)
| where OperationName == "Add application"
| mv-expand TargetResources
| project AppName = tostring(TargetResources.displayName), modifiedProps = TargetResources.modifiedProperties
| mv-apply kind=leftouter modifiedProps on (
    where modifiedProps.displayName == "AppId"
    | project AppId = parse_json(tostring(modifiedProps.newValue))[0]
)
| project AppName, AppId = coalesce(AppId, "")

关键修改说明

  1. mv-apply添加kind=leftouter:默认mv-apply是内连接,仅保留有匹配项的行;加上kind=leftouter后,所有原始行都会被保留,无匹配项的行对应字段会返回null。
  2. coalesce(AppId, "")处理空值:将null转换为空字符串,和示例数据中App2的预期结果保持一致。

示例数据验证

将示例数据代入修改后的逻辑(替换AuditLogs部分),可验证结果符合预期:

print AppName = "App1", modifiedProps = dynamic([ { "displayName": "AppId", "oldValue": "[]", "newValue": "[\"a2042ae7-b086-4738-ac37-80d7a49f270f\"]" }, { "displayName": "DisplayName", "oldValue": "[]", "newValue": "[\"App1\"]" } ])
| union (
    print AppName = "App2", modifiedProps = dynamic([ { "displayName": "AppName", "oldValue": null, "newValue": "\"App2\"" }, { "displayName": "BackendAppTimeout", "oldValue": null, "newValue": "\"Default\"" }, { "displayName": "UseHTTPOnlyCookie", "oldValue": null, "newValue": "\"False\"" } ])
)
| mv-apply kind=leftouter modifiedProps on (
    where modifiedProps.displayName == "AppId"
    | project AppId = parse_json(tostring(modifiedProps.newValue))[0]
)
| project AppName, AppId = coalesce(AppId, "")

执行后返回结果:

AppNameAppId
App1a2042ae7-b086-4738-ac37-80d7a49f270f
App2

内容的提问来源于stack exchange,提问作者swtto

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 22:10:29