如何按URI聚合Azure诊断中按耗时排序的API调用数据
问题根因
你现有查询的逻辑是直接拉取筛选后的全量请求日志,取单条请求耗时最高的20条记录,全程没有做URI维度的分组,所以同一个接口的多次高耗时请求会重复出现在结果里。
修正方案
用Kusto查询的summarize算子按requestUri_s字段分组聚合,按你的统计需求计算对应耗时值后,再排序取前20即可,每个URI只会返回一条聚合结果。
按单接口最高耗时排序(和你原查询的目标最匹配)
如果你就是要找单次调用耗时最高的20个去重接口,直接按URI分组取每组的最大耗时就行,查询语句如下:
AzureDiagnostics | where ResourceType == "APPLICATIONGATEWAYS" and OperationName == "ApplicationGatewayAccess" and requestUri_s startswith "/api" | summarize max_time_taken = max(timeTaken_d) by requestUri_s | top 20 by max_time_taken desc | project requestUri_s, max_time_taken
扩展:多性能指标聚合(适合性能排查场景)
如果除了最高耗时,你还想同时看到每个接口的平均耗时、P95耗时、调用次数这些辅助排查的指标,可以在聚合阶段同时计算多个值:
AzureDiagnostics | where ResourceType == "APPLICATIONGATEWAYS" and OperationName == "ApplicationGatewayAccess" and requestUri_s startswith "/api" | summarize max_time_taken = max(timeTaken_d), avg_time_taken = avg(timeTaken_d), p95_time_taken = percentile(timeTaken_d, 95), request_count = count() by requestUri_s | top 20 by max_time_taken desc | project requestUri_s, max_time_taken, avg_time_taken, p95_time_taken, request_count
效果验证
用你给出的样例数据跑第一个修正后的查询,返回结果如下,完全没有重复URI:
| Uri | max_time_taken |
|---|---|
| /api/path_1 | 40352 |
| /api/path_2 | 35792 |
内容的提问来源于stack exchange,提问作者Artyom Danilin
相关产品推荐
相关产品推荐

