You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Azure Resource Graph查询公网IP及关联订阅、资源类型信息

Azure Resource Graph 全量公网IP关联资源查询方案

以下优化后的查询覆盖了VM、应用网关、公网负载均衡、VPN网关、NAT网关、Azure防火墙等主流绑定公网IP的资源类型,同时支持输出订阅名称、关联资源类型、公网IP地址等你需要的信息:

Resources
// 第一步:提取所有公网IP资源基础信息
| where type =~ 'microsoft.network/publicipaddresses'
| extend publicIpAddress = tostring(properties.ipAddress)
| extend ipConfigId = tolower(tostring(properties.ipConfiguration.id))
| extend subscriptionName = subscriptionDisplayName
| project publicIpId = tolower(id), subscriptionName, publicIpAddress, location, ipConfigId
// 第二步:关联公网IP绑定的IP配置所属的上层资源
| join kind=leftouter (
    Resources
    | extend ipConfigId = tolower(tostring(properties.ipConfigurations[0].id))
    | project ipConfigId, parentResourceId = tolower(id), parentResourceType = type, parentResourceName = name
) on ipConfigId
// 第三步:针对网卡类型的上层资源,进一步关联对应的虚拟机
| extend relatedResourceType = case(
    parentResourceType =~ 'microsoft.network/networkinterfaces', 'VirtualMachine',
    parentResourceType =~ 'microsoft.network/applicationgateways/frontendipconfigurations', 'ApplicationGateway',
    parentResourceType =~ 'microsoft.network/loadbalancers/frontendipconfigurations', 'LoadBalancer',
    parentResourceType =~ 'microsoft.network/vpngateways/ipconfigurations', 'VPNGateway',
    parentResourceType =~ 'microsoft.network/natgateways/frontendipconfigurations', 'NatGateway',
    parentResourceType =~ 'microsoft.network/azurefirewalls/ipconfigurations', 'AzureFirewall',
    isempty(parentResourceType), 'Unattached',
    parentResourceType
)
| extend vmNicId = iif(parentResourceType =~ 'microsoft.network/networkinterfaces', parentResourceId, '')
| join kind=leftouter (
    Resources
    | where type =~ 'microsoft.compute/virtualmachines'
    | extend nicId = tolower(tostring(properties.networkProfile.networkInterfaces[0].id))
    | project nicId, vmName = name
) on $left.vmNicId == $right.nicId
// 统一合并关联资源名称
| extend relatedResourceName = case(
    relatedResourceType == 'VirtualMachine', coalesce(vmName, 'UnboundNic'),
    not(isempty(parentResourceName)), split(parentResourceName, '/')[0],
    'Unattached'
)
// 输出最终需要的字段
| project subscriptionName, relatedResourceType, relatedResourceName, publicIpAddress, location, publicIpId
| sort by subscriptionName, relatedResourceType

逻辑说明

  • 先从公网IP资源维度拉取全量数据,避免漏查未绑定资源的空闲公网IP
  • 反向关联公网IP绑定的IP配置所属上层资源,覆盖主流公网IP绑定场景
  • 针对网卡绑定公网IP的场景,额外关联网卡对应的虚拟机资源,直接展示VM名称而非网卡名称
  • 支持扩展其他资源类型,只需在relatedResourceType的case判断中新增对应资源类型匹配规则即可

返回字段说明

  • subscriptionName:公网IP所属的订阅名称
  • relatedResourceType:公网IP绑定的业务资源类型,无绑定时显示Unattached
  • relatedResourceName:绑定的业务资源名称
  • publicIpAddress:公网IP的地址值
  • location:资源部署的Azure区域
  • publicIpId:公网IP的资源ID,可直接用于Azure门户搜索定位资源

内容的提问来源于stack exchange,提问作者Hope sull

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 17:45:09