如何实现Azure Log Analytics日志追加时的单次告警触发?
Absolutely! You can fix the duplicate alert issue and meet your requirement of hourly checks with one-time alerts per new log entry—either by leveraging Kusto's built-in alerting variables or (if you prefer) row numbers. Let's break this down clearly:
Core Solution: Use Built-in Alert Time Tracking (Recommended)
This approach is more reliable than row numbers because it doesn’t depend on your log data having a consistent auto-incrementing row ID. Instead, it uses Azure Monitor’s @LastAlertTime variable, which automatically tracks the last time your alert ran. This ensures you only query for entries added after the last check, so each new entry triggers an alert exactly once.
Here’s the adjusted Kusto query:
LogAppend_CL | where RawData contains "for Document number" // Only include entries added since the last alert ran | where ingestion_time() > @LastAlertTime // Optional: Extract the document number to make alert notifications more useful | project Timestamp = ingestion_time(), RawData, DocumentNumber = extract(@"for Document number (\d+)", 1, RawData)
Why this works:
@LastAlertTimeis a built-in variable that gets updated every time your alert evaluates. It ensures you never reprocess the same log entries.ingestion_time()gives you the exact time the log entry was ingested into Azure Monitor, so you’re reliably filtering for new content.
Alternative: Using Row Numbers (If You Have a Reliable Auto-Increment Column)
If your LogAppend_CL table has a consistent, auto-incrementing row identifier (like a RowId column that increases with each new entry), you can use that to track new entries instead. This works by storing the highest row ID from the last alert and only querying entries above that value.
Here’s how that query would look:
// Get the highest row ID from the last set of alerted entries let last_max_rowid = toscalar( LogAppend_CL | where RawData contains "for Document number" | summarize max(RowId) ); // Only return entries with a row ID higher than the last max LogAppend_CL | where RawData contains "for Document number" | where RowId > last_max_rowid | project Timestamp = ingestion_time(), RawData, RowId, DocumentNumber = extract(@"for Document number (\d+)", 1, RawData)
⚠️ Note: This method relies entirely on your log data having a perfect auto-incrementing row ID. If rows can be deleted or IDs aren’t strictly sequential, you might miss entries or get duplicates.
Alert Configuration Adjustments
No matter which query you use, you need to update your alert settings to match your hourly check requirement:
- Set Evaluation frequency to
60 minutes(this is how often the alert runs to check for new entries). - Set Window size to
60 minutes(this ensures the query looks back over the full hour since the last check). - Keep the trigger condition as
Number of results > 0—this will fire the alert only when there are new entries to report.
This combination ensures you get an alert every hour only if there are new log entries, and each entry is alerted exactly once.
内容的提问来源于stack exchange,提问作者Adam Briers

