You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用az cli创建scheduled-query告警时--condition参数异常求助

AZ CLI 计划查询告警--condition参数配置修正

问题原因

你当前的--condition参数存在几个核心问题:

  1. 聚合点数量不匹配:窗口大小(--window-size)和评估频率(--evaluation-frequency)都是5分钟,查询按5分钟bin聚合,每个评估周期只有1个聚合点,但你写了1 violations out of 5,逻辑矛盾导致报错。
  2. 引号转义冗余:bash环境下用双引号包裹--condition时,内部字段名不需要额外加单引号转义。
  3. 目标资源类型错误:"Kubernetes service"不是AZ CLI识别的规范资源类型,需要使用完整命名空间格式。

修正后的命令

az monitor scheduled-query create \
  --condition "avg AggregatedValue > 1 at least 1 violations out of 1 aggregated points" \
  --condition-query "KubeEvents 
| where ClusterName =~ 'esg-aks-asse-aks-d'
| where ObjectKind =~ 'Pod'
| where Reason =~ 'BackOff'
| project TimeGenerated, Name, ObjectKind, Reason, Message, Namespace, Count
| summarize AggregatedValue=sum(Count) by bin(TimeGenerated, 5m)" \
  --name "esg-txc-dev-podbackoff" \
  --resource-group "<myrg>" \
  --scopes "<myscope>" \
  --target-resource-type "Microsoft.ContainerService/managedClusters" \
  --action-groups "<myactiongroup>" \
  --description "Pod Back Off Alert" \
  --evaluation-frequency "5m" \
  --severity 2 \
  --skip-query-validation false \
  --window-size "5m"

与Portal UI的对应配置逻辑

  • 聚合类型:对应--condition中的avg/sum/min/max等函数,和Portal里的“聚合类型”选项完全一致。
  • 阈值:对应> 1部分,匹配Portal里的“阈值”输入框设置。
  • 违反次数规则:at least X violations out of Y aggregated points,其中Y的计算方式为窗口大小 ÷ 评估频率,比如窗口15分钟、评估频率5分钟时Y=3,对应Portal里的“连续违反次数”或“总违反次数”选项。
  • 简化写法:当Y=1(窗口和评估频率一致)时,可直接简写为"avg AggregatedValue > 1",默认匹配1次违反规则。

内容的提问来源于stack exchange,提问作者Water

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.23 05:33:17