You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Kusto Query Language自动遍历对象数组提取名称?

KQL自动遍历JSON对象数组提取字段的解决方案

你可以使用KQL的mv-expand运算符自动展开JSON数组,无需手动指定索引。以下是替代手动实现的完整代码:

Events
| extend EntitiesArray = parse_json(Entities)
| mv-expand EntitiesArray
| extend AllEntities = tostring(EntitiesArray.Name)
| where isnotempty(AllEntities)
| summarize count() by AllEntities

代码说明:

  • extend EntitiesArray = parse_json(Entities):将Entities列的JSON字符串解析为动态数组类型,为后续处理做准备。
  • mv-expand EntitiesArray:把数组中的每个对象单独展开为一行记录。比如原表中Ev1对应2个账户对象,这一步会生成2条Ev1的记录,每条对应一个账户对象。
  • extend AllEntities = tostring(EntitiesArray.Name):从展开后的单个对象中提取Name字段,并转换为字符串类型。
  • where isnotempty(AllEntities):过滤掉Name为空的无效记录,确保统计结果准确。
  • summarize count() by AllEntities:按提取出的Name分组,统计每个名称出现的次数。

这种方式可以自动适配Entities数组中任意数量的对象,不需要手动添加Entities1、Entities2这类索引字段,完全解决了手动遍历的局限性。

内容的提问来源于stack exchange,提问作者ilyés Tabessi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 13:30:54