Kusto查询如何拆分customDimensions为3个JSON并投影输出
Kusto查询拆分customDimensions为多个独立JSON列实现方案
报错原因
你之前调用dynamic_to_json(dynamic({'x': customDimensions['x'] }))抛出it should end with '}'错误,核心原因是Kusto中dynamic()函数仅支持传入静态常量值构造字面量,不支持在参数内直接引用行级别的字段变量,和括号书写是否正确无关。
正确实现方法
使用Kusto内置的pack()函数构造JSON对象,该函数接收一组键值对参数,返回打包好的dynamic类型JSON结构,完全支持引用行字段、自定义维度属性,适配你的拆分需求。
完整可运行示例代码
requests | where customDimensions has "Scope" and customDimensions["Scope"] != "Unauthenticated" and cloud_RoleName == "cloud1" // 提前提取需要的自定义维度字段,可省略,直接写在pack中也可 | extend x = tostring(customDimensions["x"]), y = tostring(customDimensions["y"]), z = tostring(customDimensions["z"]), r = tostring(customDimensions["r"]), t = tostring(customDimensions["t"]), p = tostring(customDimensions["p"]), w = tostring(customDimensions["w"]), m = tostring(customDimensions["m"]), n = tostring(customDimensions["n"]) // 按规则打包三个独立JSON对象 | extend json1 = pack("x", x, "y", y, "z", z), json2 = pack("r", r, "t", t, "p", p), json3 = pack("w", w, "m", m, "n", n) // 投影输出最终结果 | project json1, json2, json3
补充说明
- 若需要将requests表的原生字段(比如
timestamp、id、duration等)加入对应JSON,直接在pack()参数中追加键值对即可,例如要把请求生成时间加入json1,可写为pack("x", x, "y", y, "z", z, "requestTime", timestamp) - 若需要输出字符串格式的JSON而非dynamic类型,在
pack()外层套tostring()即可,例如tostring(pack("x", x, "y", y, "z", z)) - 若某个字段不存在于customDimensions中,打包时会自动赋值为null,不会抛出语法错误
内容的提问来源于stack exchange,提问作者Sandeep Ranjan
相关产品推荐
相关产品推荐

