You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
let startTimestamp = ago(1h);
KubePodInventory
| where TimeGenerated > startTimestamp
| project ContainerID, PodName=Name
| distinct ContainerID, PodName
| join
(
ContainerLog
| where TimeGenerated > startTimestamp
)
on ContainerID
// at this point before the next pipe, columns from both tables are available to be "projected". Due to both
// tables having a "Name" column, we assign an alias as PodName to one column which we actually want
| project TimeGenerated, PodName, LogEntry, LogEntrySource
| order by TimeGenerated desc
Search within custom dimensions
traces
| wheretimestamp> ago(5d)
| where cloud_RoleName =="foo-service"
| where customDimensions["X-B3-TraceId"] =="foobar"
Mimic group by
let window = 5m;
let eventTime = todatetime('2021-12-22T15:13:38.544Z');
traces
| union exceptions
| wheretimestamp between ((eventTime - window) .. (eventTime + window))
| order bytimestampdesc
| summarize entries = make_list(pack_all()) by cloud_RoleName
Search within a time window
let window = 1m;
let eventTime = todatetime("2021-12-22T15:13:00");
traces
| union exceptions
| wheretimestamp between ((eventTime - window) .. (eventTime + window))
| order bytimestampdesc