Log Analytics关联VMProcess与Perf表查找高资源消耗PID方案咨询
关联Log Analytics Perf表与VMProcess表定位高CPU占用PID方案
方案1:直接通过VMProcess表获取(无需关联)
- VMProcess表原生包含
PercentProcessorTime字段,该字段为对应进程的CPU使用率采样值,无需额外关联Perf表即可直接筛选高资源消耗进程,同时可直接获取PID、ExecutablePath、CommandLine等细粒度属性。 - 参考KQL查询示例:
VMProcess | where TimeGenerated > ago(1h) | where ExecutablePath has "你的服务可执行文件名" // 替换为实际业务进程名 | project TimeGenerated, Computer, ProcessId, ProcessName, ExecutablePath, CommandLine, PercentProcessorTime, WorkingSetBytes | sort by PercentProcessorTime desc | take 20 // 取TOP20高CPU占用进程
方案2:Perf表与VMProcess表关联查询
如果需要更长时间周期的聚合CPU数据,可以通过以下规则关联两张表:
- 公共关联维度:
Computer字段 + 1分钟内的时间窗口(两张表的采样时间差一般不超过1分钟) - 进程匹配规则:Perf表中Process类别的InstanceName格式为
进程名#序号,该序号为同可执行名的进程启动排序,可与VMProcess表中同进程名的进程列表按启动时间排序后的序号匹配 - 关联查询示例:
// 第一步:从Perf表获取进程CPU指标 let PerfProcessData = Perf | where TimeGenerated > ago(1h) | where ObjectName == "Process" and CounterName == "% User Time" | where InstanceName startswith "Service" // 替换为实际的进程前缀 | extend InstanceNameParts = split(InstanceName, "#") | extend BaseProcessName = tostring(InstanceNameParts[0]), ProcessSeq = iff(array_length(InstanceNameParts) > 1, toint(InstanceNameParts[1]), 0) | project PerfTime = TimeGenerated, Computer, BaseProcessName, ProcessSeq, CpuUsage = CounterValue; // 第二步:从VMProcess表获取进程明细 let VMProcessData = VMProcess | where TimeGenerated > ago(1h) | where ProcessName startswith "Service" // 替换为实际的进程前缀 | project VMTime = TimeGenerated, Computer, ProcessName, ProcessId, ExecutablePath, CommandLine, PercentProcessorTime; // 第三步:按机器、时间窗口、进程序号关联 PerfProcessData | join kind=inner (VMProcessData) on Computer | where abs(datetime_diff('second', PerfTime, VMTime)) < 60 // 时间差控制在1分钟内 | partition by Computer, PerfTime, BaseProcessName, ProcessSeq ( top 1 by VMTime desc // 取时间最接近的进程明细 ) | project TimeGenerated = PerfTime, Computer, ProcessId, ProcessName, ExecutablePath, CommandLine, CpuUsage | sort by CpuUsage desc
注意事项
- 上述查询中的进程名前缀、时间范围可根据实际业务场景调整
- 若代理采样存在延迟,可适当放大时间窗口的匹配阈值
内容的提问来源于stack exchange,提问作者arrrghhh
相关产品推荐
相关产品推荐

