處理進位搜尋錯誤Handle advanced hunting errors

重要

已改善的 Microsoft 365 安全性中心 現在已提供公開預覽。The improved Microsoft 365 security center is now available in public preview. 這種新的經驗會將 Defender、Office 365 的 Defender、Microsoft 365 Defender 等,帶入 Microsoft 365 的安全性中心。This new experience brings Defender for Endpoint, Defender for Office 365, Microsoft 365 Defender, and more into the Microsoft 365 security center. 安全小組現在可以管理所有端點、電子郵件及跨產品調查、設定和修正,而不需要流覽個別的產品入口網站。Security teams can now manage all endpoint, email and cross product investigations, configuration and remediation without the need to navigate to separate product portals. 深入瞭解已變更的專案。Learn more about what's changed.

進位搜尋會顯示錯誤,以通知語法錯誤,每當查詢達到預先定義的配額和使用量參數時。Advanced hunting displays errors to notify for syntax mistakes and whenever queries hit predefined quotas and usage parameters. 請參閱下表,以瞭解如何解決或避免錯誤的秘訣。Refer to the table below for tips on how to resolve or avoid errors.

錯誤類型Error type 原因Cause 解決方案Resolution 錯誤訊息範例Error message examples
語法錯誤Syntax errors 查詢包含無法辨識的名稱,包括參照非運算子、資料行、函數或資料表。The query contains unrecognized names, including references to nonexistent operators, columns, functions, or tables. 確保 參照到 Kusto 運算子和 函數正確無誤。Ensure references to Kusto operators and functions are correct. 檢查 正確進 位搜尋欄、函數和表格的架構。Check the schema for the correct advanced hunting columns, functions, and tables. 以引號括住變數字串,以便識別這些字串。Enclose variable strings in quotes so they are recognized. 撰寫查詢時,請使用 IntelliSense 的自動完成建議。While writing your queries, use the autocomplete suggestions from IntelliSense. A recognition error occurred.
語式錯誤Semantic errors 當查詢使用有效的運算子、資料行、函數或資料表名稱時,其結構及產生的邏輯會發生錯誤。While the query uses valid operator, column, function, or table names, there are errors in its structure and resulting logic. 在某些情況下,進位搜尋會識別導致錯誤的特定運算子。In some cases, advanced hunting identifies the specific operator that caused the error. 檢查查詢結構的錯誤。Check for errors in the structure of query. 請參閱 Kusto 檔以 尋求指引。Refer to Kusto documentation for guidance. 撰寫查詢時,請使用 IntelliSense 的自動完成建議。While writing your queries, use the autocomplete suggestions from IntelliSense. 'project' operator: Failed to resolve scalar expression named 'x'
超時Timeouts 查詢只能在限定時間內 執行,才能在計時之前執行。執行複雜的查詢時,可能會更頻繁地發生此錯誤。A query can only run within a limited period before timing out. This error can happen more frequently when running complex queries. 優化查詢Optimize the query Query exceeded the timeout period.
CPU 節流CPU throttling 同一租使用者中的查詢已超過根據租使用者大小配置 CPU 資源。Queries in the same tenant have exceeded the CPU resources that have been allocated based on tenant size. 此服務每 15 分鐘和每天檢查 CPU 資源使用量,並且會在使用量超過已配置配額的 10% 時顯示警告。The service checks CPU resource usage every 15 minutes and daily and displays warnings after usage exceeds 10% of the allocated quota. 如果您達到 100% 的使用率,服務會進行查詢,直到下一個每天或 15 分鐘迴圈之後。If you reach 100% utilization, the service blocks queries until after the next daily or 15-minute cycle. 優化您的查詢以避免達到 CPU 配額Optimize your queries to avoid hitting CPU quotas - This query used X% of your organization's allocated resources for the current 15 minutes.
- You have exceeded processing resources allocated to this tenant. You can run queries again in <duration>.
超出結果大小限制Result size limit exceeded 查詢的結果集匯總大小已超過上限。The aggregate size of the result set for the query has exceeded the maximum size. 如果結果集太大,以 10,000 記錄限制截斷,但無法將結果集縮減到可接受的大小,就可能會發生此錯誤。This error can occur if the result set is so large that truncation at the 10,000-record limit can't reduce it to an acceptable size. 具有大量內容之多個欄的結果較容易受此錯誤影響。Results that have multiple columns with sizable content are more likely to be impacted by this error. 優化查詢Optimize the query Result size limit exceeded. Use "summarize" to aggregate results, "project" to drop uninteresting columns, or "take" to truncate results.
過度資源耗用Excessive resource consumption 查詢已耗用過多資源,而且已停止完成。The query has consumed excessive amounts of resources and has been stopped from completing. 在某些情況下,進一步搜尋會識別未優化的特定運算子。In some cases, advanced hunting identifies the specific operator that wasn't optimized. 優化查詢Optimize the query -Query stopped due to excessive resource consumption.
-Query stopped. Adjust use of the <operator name> operator to avoid excessive resource consumption.
未知的錯誤Unknown errors 查詢失敗的原因不明。The query failed because of an unknown reason. 再次嘗試執行查詢。Try running the query again. 如果查詢繼續傳回未知的錯誤,請透過入口網站與 Microsoft 聯繫。Contact Microsoft through the portal if queries continue to return unknown errors. An unexpected error occurred during query execution. Please try again in a few minutes.