当前位置:网站首页>Use KUSTO query statement (KQL) to query LOG on Azure Data Explorer Database
Use KUSTO query statement (KQL) to query LOG on Azure Data Explorer Database
2022-08-05 10:24:00 【zyypjc】
目录
(一)前言
Recently, the company will usually store one inAzurein a managed instanceAudit_logThe entire table is migrated toAzure Data Explorer Database来存储.So in this article, I will first summarizeAzure Data Explorer Database的基本概念,Then I will try to illustrate it with a simple example.
(二)Azure Data Explorer介绍及应用
Companies are generating and storing vast amounts of data every day. This data can be unstructured(例如音频,视频),半结构化的(例如XML,JSON)或结构化的(例如数字,日期,字符串). Data professionals are always looking for efficient techniques to process large volumes of disparate data. Although we can certainly use a traditional data warehouse,Hadoop,Sparkand other analytical tools to do this,But before exploring and analyzing the data,This will involveTB级和PBlevel dataETL的常规方法.所以,A platform is desperately needed,The platform will enable users to rapidly leverage and analyze various raw data,And ingest data quickly and get the best performance. Let's solve this situation with an interesting data analysis service.
1. 什么是Azure Data Explorer?
AzureData Browser akaADX,is used for logging,Fast telemetry and streaming data,Highly scalable and fully managed data analytics service. Browse services through this data,You can aggregate,Store and analyze various data. You can query the number in secondsTB的数据,It allows fast ad hoc queries on all kinds of data.
在Azure Data ExplorerThe tools above were formerly known as “代号为Kusto”,使用类似SQLThe query language of ieKusto查询语言(KQL)来分析来自IoT设备,应用程序,Fast-moving data for websites, etc.KQLNot limited to using functions and hundreds of operators such as aggregation,过滤等,It also includes built-in machine learning capabilities,例如聚类,回归等.
ADX使用SSDStore as cache andAzure BlobPersistent storage in storage,Works on the principle of isolation between compute and storage. It is fully managed“平台即服务(PaaS)”,Make users focus only on their data and queries. 为了说明ADX的主要优势之一,The next advantage is highlighted here,即时间序列分析:它
非常方便,And provides a lot of functions to analyze,Identify trends and anomalies.
2. 实战案例
(1)案例背景
Query the user of a key system of the companyAudit_log,and import logs(CSV)
(2)进入Azure Data Explorer主页面

(3)点击Query
点击后,See it on the rightKQLThe entered query area,You can edit the query in it

同时,In the middle area, you can view the objects you want to query just like selecting the database and the tables under the database

(4)输入查询的KQL
如下KQLThe purpose is to pull outAuditLogs表的前10000行
AuditLogs
| take 10000
(5)导出功能
Right-click in the query results area,See the list of export functions

边栏推荐
- STM32+ULN2003 drives 28BYJ4 stepper motor (forward and reverse according to the number of turns)
- 单片机:温度控制DS18B20
- Development common manual link sharing
- QSS 选择器
- Common operations of oracle under linux and daily accumulation of knowledge points (functions, timed tasks)
- 第六章:activiti流程分流判断之排它网关和并行网关
- Four years of weight loss record
- [Office] Collection of Microsoft Office download addresses (offline installation and download of Microsoft's official original version)
- 【综合类型第 35 篇】程序员的七夕浪漫时刻
- 数分面试(一)----与业务相关
猜你喜欢

Still looking for a network backup resources?Hurry up to collect the following network backup resource search artifact it is worth collecting!

JS introduction to reverse the recycling business network of learning, simple encryption mobile phone number

这份阿里强推的并发编程知识点笔记,将是你拿大厂offer的突破口

NowCoderTOP35-40——持续更新ing

【MindSpore Easy-Diantong Robot-01】You may have seen many knowledge quiz robots, but this one is a bit different

STM32+ULN2003驱动28BYJ4步进电机(根据圈数正转、反转)

基于MindSpore高效完成图像分割,实现Dice!

three.js调试工具dat.gui使用

hcip BGP enhancement experiment

多线程(进阶) - 2.5w字总结
随机推荐
60行从零开始自己动手写FutureTask是什么体验?
Meteorological data processing example - matlab string cutting matching and R language date matching (data splicing)
【Unity】【UGUI】【在屏幕上显示文本】
Can MySQL use aggregate functions without GROUP BY?
攻防世界-PWN-new_easypwn
首次去中心化抢劫?近2亿美元损失:跨链桥Nomad 被攻击事件分析
three物体围绕一周呈球形排列
【 temperature warning program DE development 】 event driven model instance
SMB + SMB2: Accessing shares return an error after prolonged idle period
RT - Thread record (a, RT, RT Thread version - Thread Studio development environment and cooperate CubeMX quick-and-dirty)
Jenkins使用手册(2) —— 软件配置
第四章:activiti RuntimeService设置获和取流程变量,及与taskService的区别,开始和完成任务时设置流程变量[通俗易懂]
第六章:activiti流程分流判断之排它网关和并行网关
什么是 DevOps?看这一篇就够了!
Go编译原理系列6(类型检查)
企业的数字化转型到底是否可以买来?
Confessing in the era of digital transformation: Mai Cong Software allows enterprises to use data in the easiest way
华为轻量级神经网络架构GhostNet再升级,GPU上大显身手的G-GhostNet(IJCV22)
第八章:activiti多用户任务分配
Pycharm 常用外部工具