在Kusto KQL中按自定义时间窗口聚合指标的问题
问题原因
你用extend调用CountMetric函数时出错,是因为extend要求生成的是标量值(单个数值/字符串等),但你的CountMetric函数返回的是一个包含count列的单行表,属于表类型,和extend的上下文要求不匹配,所以触发报错。
解决方法
方法1:将函数修改为标量函数
把函数里的聚合结果用toscalar()包裹,让函数返回单个数值而非表:
let CountMetric = (T:(Timestamp:datetime, Name:string), startTime:datetime, endTime:datetime, metricName:string) { toscalar( T | where Timestamp between(startTime..endTime) | where Name == metricName | summarize count() ) };
修改后原查询就能正常运行:
TestTimes | extend Metric1Counts = CountMetric(MyMetricsTable, start, end, "Metric1")
方法2:用Join+聚合替代函数调用
如果不想修改函数,也可以直接通过关联表的方式实现统计:
TestTimes | join kind=leftouter ( MyMetricsTable | where Name == "Metric1" ) on $left.start <= $right.Timestamp and $right.Timestamp <= $left.end | summarize Metric1Counts = countif(isnotempty(Timestamp)) by testId, start, end
这个写法会把测试时间窗口和指标表按时间范围关联,然后统计每个测试窗口内符合条件的指标数量。
内容的提问来源于stack exchange,提问作者Manu Cohen Yashar
相关产品推荐
相关产品推荐

