Private/Get-AACDashboardQuery.ps1
|
function Get-AACDashboardQuery { <# .SYNOPSIS The Azure Resource Graph queries behind Show-AACDashboard - one batch for the whole picture. .DESCRIPTION totals resources, types, resource groups, regions regions resources per region health Resource Health: resources per availability state unhealthy the unavailable and degraded resources (10) serviceIssues active Service Health events: service issues, planned maintenance, health and security advisories advisor Advisor recommendations per category and impact changes resource changes in the last -Hours, per kind recentChanges the latest 15 of them: what, who, when Every query but totals may fail (no access, a table the account can't read): the dashboard then says what it couldn't read. #> [CmdletBinding()] [OutputType([System.Collections.Specialized.OrderedDictionary])] param( [ValidateRange(1, 336)] [int] $Hours = 24 ) $since = "| extend p = properties | extend at = todatetime(p.changeAttributes.timestamp) | where at > ago($($Hours)h)" [ordered]@{ totals = "resources | summarize resources = count(), types = dcount(tolower(type)), groups = dcount(strcat(subscriptionId, '/', tolower(resourceGroup))), regions = dcount(tolower(location))" regions = 'resources | summarize resources = count() by location = tolower(location) | order by resources desc' health = "healthresources | where type =~ 'microsoft.resourcehealth/availabilitystatuses' | summarize resources = count() by state = tostring(properties.availabilityState)" unhealthy = "healthresources | where type =~ 'microsoft.resourcehealth/availabilitystatuses' | where tostring(properties.availabilityState) in~ ('Unavailable', 'Degraded') | project id, resourceId = tostring(properties.targetResourceId), state = tostring(properties.availabilityState), summary = tostring(properties.summary), reason = tostring(properties.reasonType), since = tostring(properties.occuredTime) | take 10" serviceIssues = "servicehealthresources | where type =~ 'microsoft.resourcehealth/events' | extend p = properties | where tostring(p.Status) =~ 'Active' | project id, subscriptionId, trackingId = name, title = tostring(p.Title), eventType = tostring(p.EventType), level = tostring(p.EventLevel), started = tostring(p.ImpactStartTime)" advisor = "advisorresources | where type =~ 'microsoft.advisor/recommendations' | summarize recommendations = count() by category = tostring(properties.category), impact = tostring(properties.impact)" changes = "resourcechanges $since | summarize changes = count() by changeType = tostring(p.changeType)" recentChanges = "resourcechanges $since | order by at desc | take 15 | project id, at, changeType = tostring(p.changeType), resourceId = tostring(p.targetResourceId), resourceType = tostring(p.targetResourceType), changedBy = tostring(p.changeAttributes.changedBy), operation = tostring(p.changeAttributes.operation)" } } |