You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求可正确获取跨订阅Azure Virtual Machines OS名称的Kusto查询

多订阅Azure虚拟机OS信息Kusto查询方案

以下是可正确拉取多订阅下Azure虚拟机OS信息、关联安全标签的Kusto查询语句,同时解决订阅名称、位置返回错误的问题:

Resources
// 筛选虚拟机资源类型
| where type =~ 'Microsoft.Compute/virtualMachines'
// 关联订阅容器表获取准确的订阅元数据,解决订阅名称返回错误问题
| join kind=leftouter (
    ResourceContainers
    | where type =~ 'microsoft.resources/subscriptions'
    | project subscriptionId, correctSubscriptionName = name, subscriptionState = properties.state
) on subscriptionId
// 提取OS核心属性
| extend osType = tostring(properties.storageProfile.osDisk.osType)
| extend marketPlaceOsSku = strcat(
    tostring(properties.storageProfile.imageReference.offer),
    ' ',
    tostring(properties.storageProfile.imageReference.sku)
)
// 兼容自定义镜像场景的OS名称补全
| extend osFullName = case(
    isempty(marketPlaceOsSku) or marketPlaceOsSku contains 'custom', strcat(osType, ' 自定义镜像'),
    marketPlaceOsSku
)
// 提取安全标签,可根据实际标签键修改字段名
| extend securityLevel = tostring(tags['安全等级']), dataClassification = tostring(tags['数据分类'])
// 输出字段可按需增减
| project
    correctSubscriptionName,
    subscriptionId,
    vmName = name,
    vmLocation = location,
    osType,
    osFullName,
    securityLevel,
    dataClassification,
    resourceId = id
| order by correctSubscriptionName asc, vmName asc

使用注意事项

  • 如需限定查询指定订阅,可在第一个where条件后新增规则:| where subscriptionId in ('订阅ID1', '订阅ID2'),查询结果更精准
  • 安全标签的键名请根据业务实际配置修改,示例中使用的安全等级、数据分类为通用配置,可直接替换为你业务中使用的标签键
  • 如需查询Azure Arc托管虚拟机的OS信息,可新增字段提取规则:| extend arcOsName = tostring(properties.extended.instanceView.osName),可获取到Arc代理上报的精准OS版本
  • 执行查询前请确保当前账号具备目标订阅的读者及以上权限,否则会出现部分订阅数据缺失的情况

内容的提问来源于stack exchange,提问作者info2m

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 00:15:10