You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Microsoft Defender中使用KQL连接两个表时遇语义错误求助

修复Microsoft Defender KQL中的Join语义错误

问题出在你的join子句语法上:你把右表的匹配字段$right.AccountUpn用注释符号--注释掉了,导致on后仅保留左表字段,缺少完整的等式匹配条件,违反了KQL的join语法规则。

KQL的join语法要求在on后明确写出左右表字段的等式关系,格式为$left.左表字段 == $right.右表字段。

修正后的完整查询语句如下:

EmailEvents
| where EmailDirection == "Inbound"
| where Subject == "invoice" or SenderFromAddress == "testtest@outlook.com"
| project RecipientEmailAddress, Subject, InternetMessageId, SenderFromAddress
| join kind=inner (
    IdentityInfo 
    | distinct AccountUpn, AccountDisplayName, JobTitle, Department, City, Country
) on $left.RecipientEmailAddress == $right.AccountUpn

补充说明:

如果存在邮箱格式不统一的情况(比如大小写差异、域名后缀不一致),可以用tolower()函数统一转换后再匹配,避免漏匹配:

on tolower($left.RecipientEmailAddress) == tolower($right.AccountUpn)

内容的提问来源于stack exchange,提问作者DB67

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.22 18:34:01