You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过ARM向Azure Log Analytics添加查询?

使用ARM模板向Azure Log Analytics添加保存的查询

要通过ARM模板给Log Analytics工作区添加保存的查询,你需要使用Microsoft.OperationalInsights/workspaces/savedSearches这个资源类型,以下是具体实现步骤和示例:

1. 完整ARM模板示例

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspaceName": {
      "type": "string",
      "metadata": {
        "description": "目标Log Analytics工作区名称"
      }
    },
    "savedSearchName": {
      "type": "string",
      "metadata": {
        "description": "保存查询的内部标识名称(请勿含特殊字符)"
      }
    },
    "savedSearchDisplayName": {
      "type": "string",
      "metadata": {
        "description": "Log Analytics界面中显示的查询名称"
      }
    },
    "query": {
      "type": "string",
      "metadata": {
        "description": "要保存的Kusto查询语句"
      }
    },
    "category": {
      "type": "string",
      "defaultValue": "自定义查询",
      "metadata": {
        "description": "查询所属的分类组"
      }
    }
  },
  "resources": [
    {
      "type": "Microsoft.OperationalInsights/workspaces/savedSearches",
      "apiVersion": "2020-08-01",
      "name": "[concat(parameters('workspaceName'), '/', parameters('savedSearchName'))]",
      "properties": {
        "displayName": "[parameters('savedSearchDisplayName')]",
        "query": "[parameters('query')]",
        "category": "[parameters('category')]",
        "tags": [
          {
            "name": "创建方式",
            "value": "ARM模板"
          }
        ],
        "version": 1
      }
    }
  ]
}

2. 关键参数说明

  • workspaceName: 目标Log Analytics工作区的名称,必须是已存在的工作区
  • savedSearchName: 保存查询的内部标识名,用于ARM资源定位,不能包含特殊字符
  • savedSearchDisplayName: 在Log Analytics界面中展示的友好查询名称
  • query: 你要保存的Kusto查询语句,比如AzureActivity | where OperationNameValue == "Microsoft.Compute/virtualMachines/write" | take 10

3. 部署模板

Azure CLI方式

az deployment group create \
  --resource-group <你的资源组名称> \
  --template-file <本地模板文件路径> \
  --parameters workspaceName=<工作区名称> savedSearchName="VMDeploymentsQuery" savedSearchDisplayName="最近的VM部署记录" query="AzureActivity | where OperationNameValue == 'Microsoft.Compute/virtualMachines/write' | take 10"

PowerShell方式

New-AzResourceGroupDeployment `
  -ResourceGroupName <你的资源组名称> `
  -TemplateFile <本地模板文件路径> `
  -workspaceName <工作区名称> `
  -savedSearchName "VMDeploymentsQuery" `
  -savedSearchDisplayName "最近的VM部署记录" `
  -query "AzureActivity | where OperationNameValue == 'Microsoft.Compute/virtualMachines/write' | take 10"

注意事项

  • 确保你拥有目标资源组和Log Analytics工作区的写入权限(比如Log Analytics Contributor角色)
  • 部署前先在Log Analytics测试查询语句,确保符合Kusto语法要求
  • 如需批量添加多个查询,只需在resources数组中新增多个savedSearches资源块即可

内容的提问来源于stack exchange,提问作者Prachi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 00:39:17