You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在KQL查询中提取CVE数组值并输出为单列?

提取Azure Graph Explorer中KQL结果的CVE数组值

原查询

securityresources
| where type == "microsoft.security/assessments/subassessments"
| extend assessmentKey = extract(".*assessments/(.+?)/.*",1,  id)
| where assessmentKey == "dbd0cb49-b563-45e7-9724-889e799fa648"

需求说明

上述查询返回的结果中,每条记录的additionalData字段下包含cve数组,需将数组中的每个CVE条目提取到名为CVE的单列中,每个CVE单独占一行。

修改后的查询

securityresources
| where type == "microsoft.security/assessments/subassessments"
| extend assessmentKey = extract(".*assessments/(.+?)/.*",1,  id)
| where assessmentKey == "dbd0cb49-b563-45e7-9724-889e799fa648"
// 展开cve数组,每个元素生成独立行
| mv-expand cve = additionalData.cve to typeof(string)
// 指定输出CVE列,可按需保留其他字段
| project CVE = cve

关键步骤说明

  • mv-expand cve = additionalData.cve to typeof(string):将嵌套在additionalData中的cve数组展开,数组内的每个CVE值会单独成为一条记录,同时明确类型为字符串避免格式问题。
  • project CVE = cve:将提取出的CVE值重命名为CVE列,仅输出该列;如果需要保留原记录的其他字段,可在project后添加字段名,例如project CVE = cve, id, name。

内容的提问来源于stack exchange,提问作者user211245

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.22 16:46:04