You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将两个Azure WAF相关KQL查询合并为单个查询?

合并KQL查询实现自动排查WAF拦截事件

当然可以将两个查询合并,通过子查询+in运算符自动筛选出目标transactionId对应的完整日志,无需手动复制ID。以下是合并后的查询:

// 合并后的查询:自动获取被拦截/检测请求的完整日志
AzureDiagnostics
| where ResourceType == "APPLICATIONGATEWAYS" and OperationName == "ApplicationGatewayFirewall"
| where Message !startswith "Mandatory"
| where transactionId_g in (
    // 子查询:筛选目标域名下被WAF拦截或检测的transactionId
    AzureDiagnostics
    | where ResourceType == "APPLICATIONGATEWAYS" and OperationName == "ApplicationGatewayFirewall"
    | where hostname_s in ('www.website.com')
    | where Message !startswith "Mandatory"
    | where action_s in ('Blocked', 'Detected')
    | project transactionId_g
)
| project transactionId_g, TimeGenerated, clientIp_s, hostname_s, requestUri_s, ruleId_s, ruleSetVersion_s, ruleGroup_s, action_s, Message, details_message_s, details_data_s
| sort by transactionId_g, TimeGenerated

逻辑说明:

  1. 子查询部分:复用原Query1的逻辑,筛选出www.website.com域名下被WAF拦截(Blocked)或检测(Detected)的所有transactionId_g。
  2. 主查询部分:从所有WAF日志中,筛选出包含子查询返回的transactionId的日志行,同时保留排查所需的核心字段。
  3. 额外添加TimeGenerated排序,便于按时间顺序查看同一事务下的请求日志,更利于定位误拦截原因。

优化建议:

如果日志量较大,建议在两个查询分支中都添加时间范围筛选(比如| where TimeGenerated between (ago(3d) and now())),可大幅提升查询效率。

内容的提问来源于stack exchange,提问作者martin81

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 03:50:24