如何在in条件中使用tabular类型?Kusto查询语法报错求助
解决Kusto查询中
in操作符与tabular类型的语法问题 你遇到的问题是因为Kusto的in操作符默认不能直接接收tabular(表)类型的变量——它需要的是一个标量值的集合(比如动态数组,或者用括号包裹的单列查询结果)。你的clusterNodes是一个包含单列Computer的表,直接写Computer in clusterNodes不符合语法要求,所以会触发解析错误。
这里有两种简单的修正方法:
方法1:用括号包裹tabular变量
直接在clusterNodes外面加上括号,明确告诉Kusto你要引用这个表的单列结果:
let clusterNodes = KubeNodeInventory | where TimeGenerated > ago(7d) | where ClusterName == "test-aks" | distinct Computer; Perf | where TimeGenerated > ago(1d) | where CounterName == "cpuUsageNanoCores" and ObjectName == "K8SNode" and Computer in (clusterNodes) | summarize ValueAvg = avg(CounterValue) by Time = bin(TimeGenerated, 15m), Counter = CounterName | project round(ValueAvg / 1000000000, 2), Time, Counter | render timechart;
方法2:将tabular转换为动态数组
把clusterNodes定义为一个包含所有Computer值的动态数组,这样可以直接和in操作符配合使用:
let clusterNodes = KubeNodeInventory | where TimeGenerated > ago(7d) | where ClusterName == "test-aks" | make_set(Computer); Perf | where TimeGenerated > ago(1d) | where CounterName == "cpuUsageNanoCores" and ObjectName == "K8SNode" and Computer in clusterNodes | summarize ValueAvg = avg(CounterValue) by Time = bin(TimeGenerated, 15m), Counter = CounterName | project round(ValueAvg / 1000000000, 2), Time, Counter | render timechart;
两种方法都能解决你的语法错误:方法1更简洁直接,适合这种简单的单列表引用场景;方法2生成的是动态数组,如果你需要在多个查询片段中复用这个值集合会更灵活。
内容的提问来源于stack exchange,提问作者Dave New
相关产品推荐
相关产品推荐

