【问题标题】:Azure Kusto Data Explorer: combine rows by columnAzure Kusto 数据资源管理器:按列组合行
【发布时间】:2020-02-18 17:46:48
【问题描述】:

我希望更新/扩展列 Process 以反映进程是否已结束。

例如,下面的表格应该返回:

Id  Process  
1   Completed
1   Completed
1   Completed   //Id 1: because the last Process state was End 
2   InProgress
2   InProgress  //Id 2: because the last Process state was not End 
3   InProgress
3   InProgress
3   InProgress
3   InProgress  //Id 3: because the last Process state was not End 

表:

datatable(Id:int, Process:string, UpdateTime: datetime))
[
    1, "Initiate", datetime(2020-02-02 12:00:00),
    1, "Start", datetime(2020-02-02 13:00:00),
    1, "End", datetime(2020-02-02 14:00:00),
    2, "Initiate", datetime(2020-02-02 12:00:00),
    2, "Start", datetime(2020-02-02 13:00:00),
    3  "Initiate", datetime(2020-02-02 12:00:00),
    3, "Start", datetime(2020-02-02 13:00:00),
    3, "End", datetime(2020-02-02 14:00:00),
    3, "Reopen", datetime(2020-02-02 15:00:00),
]

【问题讨论】:

    标签: azure-data-explorer kql


    【解决方案1】:

    您可以尝试以下方法:

    datatable(Id:int, Process:string, UpdateTime: datetime)
    [
        1, "Initiate", datetime(2020-02-02 12:00:00),
        1, "Start", datetime(2020-02-02 13:00:00),
        1, "End", datetime(2020-02-02 14:00:00),
        2, "Initiate", datetime(2020-02-02 12:00:00),
        2, "Start", datetime(2020-02-02 13:00:00),
        3, "Initiate", datetime(2020-02-02 12:00:00),
        3, "Start", datetime(2020-02-02 13:00:00),
        3, "End", datetime(2020-02-02 14:00:00),
        3, "Reopen", datetime(2020-02-02 15:00:00),
    ]
    | order by Id asc, UpdateTime asc
    | extend session_start = row_window_session(UpdateTime, 365d, 365d, Id != prev(Id))
    | as hint.materialized = true T
    | lookup (
        T
        | summarize arg_max(UpdateTime, Process) by session_start, Id
        | project Id, LastProcess = Process
    ) on Id
    | project Id, Process = case(LastProcess == "End", "Completed", "InProgress")
    

    返回:

    | Id | Process    |
    |----|------------|
    | 1  | Completed  |
    | 1  | Completed  |
    | 1  | Completed  |
    | 2  | InProgress |
    | 2  | InProgress |
    | 3  | InProgress |
    | 3  | InProgress |
    | 3  | InProgress |
    | 3  | InProgress |
    

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2020-05-09
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多