如何找出未关联资源的Azure存储账户?当前Resource Graph查询无结果
解决Azure存储账户未关联资源的查询问题
你的原查询无法返回结果的核心问题是关联条件错误:你用存储账户名称去匹配虚拟机托管磁盘ID、应用服务存储账户ID,但这些ID是完整的资源路径(比如/subscriptions/xxx/resourceGroups/xxx/providers/Microsoft.Storage/storageAccounts/xxx),和存储账户名称完全不匹配,导致关联逻辑失效。
修正后的Azure Resource Graph查询
通过leftanti join可以高效筛选出未被任何指定资源引用的存储账户,以下查询覆盖了常见的关联场景(虚拟机诊断存储、非托管磁盘存储、应用服务存储、函数应用存储):
resources | where type == "microsoft.storage/storageaccounts" | project storageId = id, storageAccountName = name, resourceGroup, location | join kind=leftanti ( // 合并所有引用存储账户的资源类型 union // 虚拟机诊断存储账户 (resources | where type == "microsoft.compute/virtualmachines" | extend diagStorageUri = tostring(properties.diagnosticsProfile.bootDiagnostics.storageUri) | where isnotempty(diagStorageUri) | parse diagStorageUri with "https://" storageAccountName ".blob.core.windows.net/" * | join kind=inner (resources | where type == "microsoft.storage/storageaccounts") on $left.storageAccountName == $right.name | project referencedStorageId = id), // 应用服务关联的存储账户 (resources | where type == "microsoft.web/sites" | extend storageId = tostring(properties.storageAccount.id) | where isnotempty(storageId) | project referencedStorageId = storageId), // 非托管磁盘使用的存储账户 (resources | where type == "microsoft.compute/virtualmachines" | extend vhdUri = tostring(properties.storageProfile.osDisk.vhd.uri) | where isnotempty(vhdUri) | parse vhdUri with "https://" storageAccountName ".blob.core.windows.net/" * | join kind=inner (resources | where type == "microsoft.storage/storageaccounts") on $left.storageAccountName == $right.name | project referencedStorageId = id), // 函数应用关联的存储账户 (resources | where type == "microsoft.web/sites/functions" | extend storageId = tostring(properties.storageAccount.id) | where isnotempty(storageId) | project referencedStorageId = storageId) ) on $left.storageId == $right.referencedStorageId | project storageAccountName, resourceGroup, location
补充说明
- 资源同步延迟:如果新建的存储账户未出现在结果中,可能是Azure Resource Graph的同步延迟(通常不超过15分钟),等待一段时间后重试即可。
- 订阅范围:确保查询时选择的订阅包含你新建的存储账户。
- 扩展关联场景:如果还有其他类型的资源会引用存储账户,可以在
union块中添加对应的查询逻辑。
是否需要PowerShell?
不需要,通过修正后的Azure Resource Graph查询即可在工作簿中直接获取结果。如果需要批量导出结果,也可以在Azure CLI中运行以下命令(基于资源图查询):
az graph query -q "上述Kusto查询语句" --output table
内容的提问来源于stack exchange,提问作者Kirsty
相关产品推荐
相关产品推荐

