You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure Monitor的Application Insights中用Kusto按天生成含搜索词的柱状图?

在Azure Monitor Application Insights中用Kusto生成按天分组柱状图

基础按天分组柱状图实现

核心是用Kusto的bin()函数将时间戳按天分组,再通过summarize聚合统计指标,最后切换到柱状图可视化。

以请求日志(requests表)为例,统计每日请求总数的查询:

requests
| where timestamp >= ago(30d)  // 限制查询最近30天数据
| summarize daily_requests = count() by bin(timestamp, 1d)  // 按天分组统计请求数
| sort by timestamp asc

执行完查询后,在Application Insights日志界面的顶部可视化选项中选择「柱状图」,即可生成按天分布的柱状图。

加入指定搜索词的查询

如果需要筛选包含特定关键词的日志,先通过where子句过滤数据,再执行分组聚合。

示例1:筛选包含指定URL的请求日志

requests
| where timestamp >= ago(14d)
| where url contains "/api/payment"  // 过滤包含指定URL的请求
| summarize daily_payment_requests = count() by bin(timestamp, 1d)
| sort by timestamp asc

示例2:筛选包含错误关键词的跟踪日志

traces
| where timestamp >= ago(7d)
| where message contains "TimeoutError"  // 过滤包含错误关键词的日志
| summarize daily_timeout_errors = count() by bin(timestamp, 1d)
| sort by timestamp asc

大量日志场景下的优化策略

当日志量极大时,直接查询会变慢甚至超时,可通过以下方式优化:

  • 缩小时间范围:尽量只查询必要的时间段,比如只查最近7天而非全量历史数据,减少扫描的数据量。
  • 利用分区过滤:Kusto表默认按时间分区,timestamp的范围过滤会自动命中分区,避免全表扫描。
  • 使用近似统计:如果不需要精确计数,用approx_count_distinct()代替count(),大幅提升聚合速度:
    requests
    | where timestamp >= ago(30d)
    | where url contains "/api/payment"
    | summarize daily_payment_requests = approx_count_distinct(id) by bin(timestamp, 1d)
    
  • 预聚合数据:如果需要长期按天统计,创建日志查询规则,定期将聚合结果写入自定义表(比如DailyPaymentRequests),后续直接查询自定义表即可,无需实时扫描原始日志:
    // 日志查询规则的查询语句,定期执行并写入目标表
    requests
    | where url contains "/api/payment"
    | summarize count() by bin(timestamp, 1d)
    
  • 优化索引:确保过滤用的字段(如url、message)开启了字段索引或全文索引,提升where子句的过滤效率。

内容的提问来源于stack exchange,提问作者user3180309

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 19:01:20