You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure Data Lake Gen2日志中获取操作对应的用户登录ID信息

解决ADLS Gen2操作日志无法获取用户ID的方案

根因说明

你遇到的DeleteFile操作缺失用户ID的问题有两个核心原因:

  • 使用的经典版诊断设置对ADLS Gen2的层级命名空间专属操作(如DeleteFile、CreatePath等)的身份字段采集支持不完整
  • AuthenticationType为AccountKey时,操作是通过存储账号密钥发起,本身未绑定AAD身份,默认不会采集用户UPN字段

具体解决步骤

  • 替换经典诊断设置为新版诊断设置
    停用现有的Diagnostic setting (classic)配置,新建普通非经典诊断设置,选择日志目标为Log Analytics工作区,勾选StorageBlobLogs下的StorageRead、StorageWrite、StorageDelete三类日志,保存配置后,所有存储操作的身份相关字段(含RequesterUpn、RequesterObjectId、RequesterAppId等)会自动补全到StorageBlobLogs表中,无需额外配置。
  • 强制所有操作使用OAuth认证(推荐)
    进入存储账号配置页,将「允许存储账号密钥访问」选项设置为禁用,所有客户端(含Azure Storage Explorer)必须使用AAD身份登录后才能操作存储资源,此时所有操作的AuthenticationType都会显示为OAuth,DeleteFile等所有操作的日志都会直接携带RequesterUpn字段,无需额外关联查询。
  • 临时兼容方案(不禁用共享密钥时使用)
    若暂时无法禁用共享密钥访问,可使用KQL关联StorageBlobLogs和AAD登录日志,直接查询到对应操作的用户ID,参考查询语句如下:
    StorageBlobLogs
    | where OperationName == "DeleteFile"
    | where TimeGenerated > ago(24h)
    | join kind=inner (
        SigninLogs
        | where TimeGenerated > ago(24h)
        | extend AuthenticationHash = tostring(AuthenticationDetails[0].authenticationStepResultDetail)
        | project AuthenticationHash, UserPrincipalName, IPAddress
    ) on $left.CallerIpAddress == $right.IPAddress and $left.AuthenticationHash == $right.AuthenticationHash
    | project TimeGenerated, OperationName, Uri, UserPrincipalName, CallerIpAddress
    

日志示例参考

日志截图

内容的提问来源于stack exchange,提问作者Erik Warming

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.28 06:06:02