Это сработало для меня, комбинирование KubePodInventory с фильтрами с оператором поиска @ Avnera показалось мне быстрым.
//# Pieter2020-06 Search for log in Namespace and Container name
let _podInventory = ( KubePodInventory
| where Namespace has "mynamesspace-uat"
| where ContainerName has_any ('pod1' , 'web2' , 'pod3')
| distinct ContainerID, ContainerName, Namespace, PodRestartCount , Name );
ContainerLog
//| where TimeGenerated between( datetime("2020-06-16 02:00:00 ") .. now())
| where TimeGenerated between( datetime("2020-07-13 19:00:00 ") .. datetime("2020-07-15 9:00:00 ") )
| where ( LogEntry has_any( "WARN", "ERRO" ) )
| lookup kind=leftouter (_podInventory) on ContainerID
| project TimeGenerated, Name1, LogEntry, Namespace