如何在KQL查询中提取CVE数组值并输出为单列?
提取Azure Graph Explorer中KQL结果的CVE数组值
原查询
securityresources | where type == "microsoft.security/assessments/subassessments" | extend assessmentKey = extract(".*assessments/(.+?)/.*",1, id) | where assessmentKey == "dbd0cb49-b563-45e7-9724-889e799fa648"
需求说明
上述查询返回的结果中,每条记录的additionalData字段下包含cve数组,需将数组中的每个CVE条目提取到名为CVE的单列中,每个CVE单独占一行。
修改后的查询
securityresources | where type == "microsoft.security/assessments/subassessments" | extend assessmentKey = extract(".*assessments/(.+?)/.*",1, id) | where assessmentKey == "dbd0cb49-b563-45e7-9724-889e799fa648" // 展开cve数组,每个元素生成独立行 | mv-expand cve = additionalData.cve to typeof(string) // 指定输出CVE列,可按需保留其他字段 | project CVE = cve
关键步骤说明
mv-expand cve = additionalData.cve to typeof(string):将嵌套在additionalData中的cve数组展开,数组内的每个CVE值会单独成为一条记录,同时明确类型为字符串避免格式问题。project CVE = cve:将提取出的CVE值重命名为CVE列,仅输出该列;如果需要保留原记录的其他字段,可在project后添加字段名,例如project CVE = cve, id, name。
内容的提问来源于stack exchange,提问作者user211245
相关产品推荐
相关产品推荐

