You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kusto如何按类型筛选资源统一查询多实例Application Insights异常数据

实现方案

这个需求可以直接通过Azure Kusto查询的跨资源通配符语法实现,不需要手动枚举每个Application Insights实例名。

方法1:资源组范围通配符查询(最简单)

直接在app()函数中传入带通配符的ARM资源路径,即可匹配指定资源组下所有符合类型的App Insights实例,示例代码如下:

// 替换为实际的订阅ID,需要查其他表把exceptions换成traces/requests等对应表名即可
union
app("/subscriptions/你的订阅ID/resourceGroups/dev/providers/microsoft.insights/components/*").exceptions,
app("/subscriptions/你的订阅ID/resourceGroups/test/providers/microsoft.insights/components/*").exceptions
| where timestamp > ago(24h)
| summarize count() by problemId, appName
| sort by count_ desc

如果需要匹配所有订阅下的dev、test资源组,把订阅ID位置也换成通配符即可:

union
app("/subscriptions/*/resourceGroups/dev/providers/microsoft.insights/components/*").exceptions,
app("/subscriptions/*/resourceGroups/test/providers/microsoft.insights/components/*").exceptions
// 后续过滤逻辑不变

方法2:复杂过滤场景(如按标签筛选资源)

如果你的资源筛选逻辑更复杂(比如需要按标签、名称关键字等动态筛选App Insights实例),可以先通过Azure Resource Graph查询得到符合条件的实例资源ID列表,再把列表代入union语句即可:

  1. 先执行资源查询获取资源ID列表:
resources
| where type =~ 'microsoft.insights/components'
| where resourceGroup in~ ('dev', 'test')
// 可以加更多过滤条件,比如按标签筛选:| where tags.env == 'test'
| project id
  1. 把得到的ID列表拼入union语句即可,Kusto支持同时传入多个app()实例做union。

注意事项

  • 执行查询的账号需要具备所有目标App Insights实例的监控数据读取权限
  • 跨实例查询返回的结果会自动携带appName字段标识数据所属的实例,无需额外处理
  • Application Insights的正确资源类型为microsoft.insights/components,过滤资源时无需额外匹配microsoft.insights(该值为资源提供者名称,不是资源类型)

内容的提问来源于stack exchange,提问作者tmaj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.05 02:12:02