如何在 Kusto 中循环访问数组?

How do I iterate through array in Kusto?

我需要在 Azure Resource Graph Explorer (https://preview.portal.azure.com/) 中循环访问托管数据磁盘。我的查询在下面,但它是 returns JSON 数组,我需要提取磁盘名称和正在使用的存储帐户类型(下面是示例 JSON return) .所以我想在屏幕上按机器名称、磁盘名称和存储帐户类型进行分组。我当前的查询如下,但显然由于 JSON

的 return 而无法正常工作
where type =~ 'Microsoft.Compute/virtualmachines' |
extend disks = properties.storageProfile.dataDisks |
project name, disks

相同的 JSON 输出

[
    {
        "name": "COMP02_DDisk1",
        "createOption": "Attach",
        "diskSizeGB": 400,
        "managedDisk": {
            "id": "/subscriptions/5f5c5be9-77d4db790171/resourceGroups/BRAZILSOUTHDB/providers/Microsoft.Compute/disks/COMP02_DDisk1",
            "storageAccountType": "Premium_LRS"
        },
        "caching": "None",
        "toBeDetached": false,
        "lun": 0,
        "writeAcceleratorEnabled": false
    },
    {
        "name": "COMP02_DDisk2",
        "createOption": "Attach",
        "diskSizeGB": 400,
        "managedDisk": {
            "id": "/subscriptions/5f5c5be9-77d4db790171/resourceGroups/BRAZILSOUTHDB/providers/Microsoft.Compute/disks/COMP02_DDisk2",
            "storageAccountType": "Premium_LRS"
        },
        "caching": "None",
        "toBeDetached": false,
        "lun": 1,
        "writeAcceleratorEnabled": false
    }
]

在这种情况下,使用 mv-expand 扩展数组然后为每条记录应用 dynamic-property 访问器通常很有帮助。

https://docs.microsoft.com/en-us/azure/kusto/query/mvexpandoperator

示例:

print d = dynamic([
    {
        "name": "COMP02_DDisk1",
        "createOption": "Attach",
        "diskSizeGB": 400,
        "managedDisk": {
            "id": "/subscriptions/5f5c5be9-77d4db790171/resourceGroups/BRAZILSOUTHDB/providers/Microsoft.Compute/disks/COMP02_DDisk1",
            "storageAccountType": "Premium_LRS"
        },
        "caching": "None",
        "toBeDetached": false,
        "lun": 0,
        "writeAcceleratorEnabled": false
    },
    {
        "name": "COMP02_DDisk2",
        "createOption": "Attach",
        "diskSizeGB": 400,
        "managedDisk": {
            "id": "/subscriptions/5f5c5be9-77d4db790171/resourceGroups/BRAZILSOUTHDB/providers/Microsoft.Compute/disks/COMP02_DDisk2",
            "storageAccountType": "Premium_LRS"
        },
        "caching": "None",
        "toBeDetached": false,
        "lun": 1,
        "writeAcceleratorEnabled": false
    }
])
| mv-expand d
| project d.name, d.managedDisk.storageAccountType

这将输出:

| d_name        | d_managedDisk_storageAccountType |
|---------------|----------------------------------|
| COMP02_DDisk1 | Premium_LRS                      |
| COMP02_DDisk2 | Premium_LRS                      |

希望你一切顺利。

您也可以尝试这种方式,首先我从整个集合中找到了网络安全组,然后过滤了 defaultSecurityRules 这又是一个数组。 在局部变量 rules 中使用 mvexpand 收集它后,您应该能够在应用后获取所需的内容。

 where type =~ "microsoft.network/networksecuritygroups"
| mvexpand rules = properties.defaultSecurityRules
| where rules.properties.destinationAddressPrefix =~ "*"

您也可以参考下面的内容link,希望对您也有帮助。