You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在in条件中使用tabular类型?Kusto查询语法报错求助

解决Kusto查询中in操作符与tabular类型的语法问题

你遇到的问题是因为Kusto的in操作符默认不能直接接收tabular(表)类型的变量——它需要的是一个标量值的集合(比如动态数组,或者用括号包裹的单列查询结果)。你的clusterNodes是一个包含单列Computer的表,直接写Computer in clusterNodes不符合语法要求,所以会触发解析错误。

这里有两种简单的修正方法:

方法1:用括号包裹tabular变量

直接在clusterNodes外面加上括号,明确告诉Kusto你要引用这个表的单列结果:

let clusterNodes = KubeNodeInventory | where TimeGenerated > ago(7d) | where ClusterName == "test-aks" | distinct Computer;
Perf 
| where TimeGenerated > ago(1d) 
| where CounterName == "cpuUsageNanoCores" and ObjectName == "K8SNode" and Computer in (clusterNodes) 
| summarize ValueAvg = avg(CounterValue) by Time = bin(TimeGenerated, 15m), Counter = CounterName 
| project round(ValueAvg / 1000000000, 2), Time, Counter 
| render timechart;

方法2:将tabular转换为动态数组

把clusterNodes定义为一个包含所有Computer值的动态数组,这样可以直接和in操作符配合使用:

let clusterNodes = KubeNodeInventory | where TimeGenerated > ago(7d) | where ClusterName == "test-aks" | make_set(Computer);
Perf 
| where TimeGenerated > ago(1d) 
| where CounterName == "cpuUsageNanoCores" and ObjectName == "K8SNode" and Computer in clusterNodes 
| summarize ValueAvg = avg(CounterValue) by Time = bin(TimeGenerated, 15m), Counter = CounterName 
| project round(ValueAvg / 1000000000, 2), Time, Counter 
| render timechart;

两种方法都能解决你的语法错误:方法1更简洁直接,适合这种简单的单列表引用场景;方法2生成的是动态数组,如果你需要在多个查询片段中复用这个值集合会更灵活。

内容的提问来源于stack exchange,提问作者Dave New

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 09:10:36