You are monitoring an e-commerce application with Application Insights. You need to analyze all exceptions that occurred in the last 24 hours, grouped by the exception type. You also need to include the URL where each exception was triggered and the number of times each type occurred. Which Log Analytics Kusto query should you use?
Trap 1: exceptions | where timestamp > ago(24h) | extend exceptionType =…
Exception data typically does not store URL in customDimensions by default. The URL is available in the requests table, not directly in exceptions. This approach is unreliable.
Trap 2: requests | where timestamp > ago(24h) and success == false | extend…
This only covers failed requests (HTTP errors), not custom exceptions caught in code. It also uses resultCode as exceptionType, which is not accurate.
Trap 3: exceptions | where timestamp > ago(24h) | extend exceptionType =…
This returns the count per exceptionType but does not include the URL, which the requirement specifies.
- A
exceptions | where timestamp > ago(24h) | join kind=inner requests on operation_Id | extend exceptionType = tostring(innermostType) | summarize Count=count() by exceptionType, url
This query joins the exceptions table with the requests table on operation_Id to get the URL (from requests table), then groups by exceptionType (innermostType) and url, counting occurrences.
- B
exceptions | where timestamp > ago(24h) | extend exceptionType = tostring(customDimensions.['ExceptionType']) | summarize Count=count() by exceptionType, url = tostring(customDimensions.['Url'])
Why it fails: Exception data typically does not store URL in customDimensions by default. The URL is available in the requests table, not directly in exceptions. This approach is unreliable.
- C
requests | where timestamp > ago(24h) and success == false | extend exceptionType = tostring(resultCode) | summarize Count=count() by exceptionType, url
Why it fails: This only covers failed requests (HTTP errors), not custom exceptions caught in code. It also uses resultCode as exceptionType, which is not accurate.
- D
exceptions | where timestamp > ago(24h) | extend exceptionType = tostring(innermostType) | summarize Count=count() by exceptionType
Why it fails: This returns the count per exceptionType but does not include the URL, which the requirement specifies.