求可正确获取跨订阅Azure Virtual Machines OS名称的Kusto查询
多订阅Azure虚拟机OS信息Kusto查询方案
以下是可正确拉取多订阅下Azure虚拟机OS信息、关联安全标签的Kusto查询语句,同时解决订阅名称、位置返回错误的问题:
Resources // 筛选虚拟机资源类型 | where type =~ 'Microsoft.Compute/virtualMachines' // 关联订阅容器表获取准确的订阅元数据,解决订阅名称返回错误问题 | join kind=leftouter ( ResourceContainers | where type =~ 'microsoft.resources/subscriptions' | project subscriptionId, correctSubscriptionName = name, subscriptionState = properties.state ) on subscriptionId // 提取OS核心属性 | extend osType = tostring(properties.storageProfile.osDisk.osType) | extend marketPlaceOsSku = strcat( tostring(properties.storageProfile.imageReference.offer), ' ', tostring(properties.storageProfile.imageReference.sku) ) // 兼容自定义镜像场景的OS名称补全 | extend osFullName = case( isempty(marketPlaceOsSku) or marketPlaceOsSku contains 'custom', strcat(osType, ' 自定义镜像'), marketPlaceOsSku ) // 提取安全标签,可根据实际标签键修改字段名 | extend securityLevel = tostring(tags['安全等级']), dataClassification = tostring(tags['数据分类']) // 输出字段可按需增减 | project correctSubscriptionName, subscriptionId, vmName = name, vmLocation = location, osType, osFullName, securityLevel, dataClassification, resourceId = id | order by correctSubscriptionName asc, vmName asc
使用注意事项
- 如需限定查询指定订阅,可在第一个
where条件后新增规则:| where subscriptionId in ('订阅ID1', '订阅ID2'),查询结果更精准 - 安全标签的键名请根据业务实际配置修改,示例中使用的
安全等级、数据分类为通用配置,可直接替换为你业务中使用的标签键 - 如需查询Azure Arc托管虚拟机的OS信息,可新增字段提取规则:
| extend arcOsName = tostring(properties.extended.instanceView.osName),可获取到Arc代理上报的精准OS版本 - 执行查询前请确保当前账号具备目标订阅的
读者及以上权限,否则会出现部分订阅数据缺失的情况
内容的提问来源于stack exchange,提问作者info2m
相关产品推荐
相关产品推荐

