在Microsoft Defender中使用KQL连接两个表时遇语义错误求助
修复Microsoft Defender KQL中的Join语义错误
问题出在你的join子句语法上:你把右表的匹配字段$right.AccountUpn用注释符号--注释掉了,导致on后仅保留左表字段,缺少完整的等式匹配条件,违反了KQL的join语法规则。
KQL的join语法要求在on后明确写出左右表字段的等式关系,格式为$left.左表字段 == $right.右表字段。
修正后的完整查询语句如下:
EmailEvents | where EmailDirection == "Inbound" | where Subject == "invoice" or SenderFromAddress == "testtest@outlook.com" | project RecipientEmailAddress, Subject, InternetMessageId, SenderFromAddress | join kind=inner ( IdentityInfo | distinct AccountUpn, AccountDisplayName, JobTitle, Department, City, Country ) on $left.RecipientEmailAddress == $right.AccountUpn
补充说明:
如果存在邮箱格式不统一的情况(比如大小写差异、域名后缀不一致),可以用tolower()函数统一转换后再匹配,避免漏匹配:
on tolower($left.RecipientEmailAddress) == tolower($right.AccountUpn)
内容的提问来源于stack exchange,提问作者DB67
相关产品推荐
相关产品推荐

