You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Monitor Log Analytics查询调整:特定操作筛选与计数阈值设置

Great questions! Let's tackle them one by one and refine your Kusto query to meet your needs.

1. Displaying both operation types (FullAccess grants AND mail/calendar deletions)

First off, using AND here doesn't make sense because a single log entry can't be both an Add-MailboxPermission action and a delete operation—these are two distinct event types. To show both categories of events, you need to keep using OR, but we can make the filter more precise to avoid matching irrelevant operations:

OfficeActivity
// Target the two specific operation groups we care about
| where 
    // Match Add-MailboxPermission actions that grant FullAccess
    (Operation == "Add-MailboxPermission" and parse_json(Parameters)[2].Value contains "FullAccess")
    OR
    // Match mail/calendar delete/remove operations
    (Operation has_any("Delete", "Remove") and (Operation contains "Calendar" or Operation contains "Message"))

Why this works:

  • We explicitly isolate Add-MailboxPermission events and validate the FullAccess permission parameter, so we don't accidentally pick up other mailbox permission changes.
  • For deletions, we use has_any to cover both "Delete" and "Remove" operations, then narrow it down to only calendar or mail-related actions (to skip unrelated delete events like folder deletions).

If your goal was to find users who performed both actions in the same 30-minute window, that's a different use case—we'd need to group by user and time first, then check for both operation types. But based on your original query, it looks like you just want to show all events from either category, so the OR logic above is correct.

2. Filtering to only keep results with count ≥10

This is straightforward—you don't need any special functions, just add a where clause after your summarize step to filter the grouped counts:

Full refined query combining both fixes:

OfficeActivity
| where 
    (Operation == "Add-MailboxPermission" and parse_json(Parameters)[2].Value contains "FullAccess")
    OR
    (Operation has_any("Delete", "Remove") and (Operation contains "Calendar" or Operation contains "Message"))
// Group by 30-minute intervals, operation type, and user, then count events
| summarize Events=count() by bin(TimeGenerated, 30m), Operation, UserId
// Keep only groups with 10 or more events
| where Events >= 10
// Optional: Sort results to prioritize recent, high-count events
| sort by TimeGenerated desc, Events desc

How this works:

  • The summarize step calculates the number of events per 30-minute window, operation, and user.
  • The subsequent where Events >=10 filters out any groups that don't meet your minimum count threshold.

内容的提问来源于stack exchange,提问作者Maciej Jakubczak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:28:26