如何从KQL查询结果中移除特定文本(如<br>)?
移除KQL查询结果中的
<br>文本 可以使用KQL的replace_string()函数,将目标字段中的<br>字符串替换为空值,就能移除这些文本。针对你的查询,只需要对包含<br>的Vulnerabilities和Remediations字段做处理即可。
修改后的完整查询:
| where type == "microsoft.security/assessments" | project id = tostring(id), Vulnerabilities = replace_string(properties.metadata.description, "<br>", ""), Severity = properties.metadata.severity, Remediations = replace_string(properties.metadata.remediationDescription, "<br>", "") | parse kind=regex id with '/virtualMachines/' Name '/providers/' | where isnotempty(Name) | project Name, Severity, Vulnerabilities, Remediations
补充说明
replace_string(原字段, 要替换的文本, 替换后的文本):该函数会批量替换字段中所有匹配的目标文本,这里通过将<br>替换为空字符串实现移除效果。- 如果字段中存在大小写不同的
<BR>,可以改用正则替换忽略大小写:replace_regex(properties.metadata.description, @"(?i)<br>", "")
内容的提问来源于stack exchange,提问作者dehgrah101
相关产品推荐
相关产品推荐

