FREE STUDY NOTES · DP-700

Tumbling, hopping, sliding, session and snapshot windows in Fabric eventstreams

How the five eventstream window types group events in time, how they overlap and how to write them in the SQL operator.

From Ultra Transcenders DP-700 by Tony Rough (coming December 2026)

Windows group events by time so you can aggregate them. Eventstreams inherit Azure Stream Analytics windowing, so the five classic window types apply.

Eventstream windows appear in the no-code Group by operator (time window plus grouping fields; Learn’s migration guide lists tumbling, hopping and sliding patterns there) and in full in the SQL operator, where a window function goes in the GROUP BY clause. Every window emits its result at the end of the window, timestamped with the window end (System.Timestamp()), and windows align to the zeroth hour. A window’s maximum size is seven days.

Window Definition Overlap Syntax (SQL operator)
Tumbling Fixed-size, contiguous, non-overlapping intervals None: each event is in exactly one window TumblingWindow(minute, 5)
Hopping Fixed size that hops forward by a set period Yes when hop is smaller than size; hop equal to size is a tumbling window HoppingWindow(minute, 10, 5)
Sliding Emits only when an event enters or leaves the window Yes; every window contains at least one event SlidingWindow(minute, 10)
Session Starts at the first event, extends while events arrive within the timeout, closes at the timeout or maximum duration No; gaps with no data are filtered out SessionWindow(minute, 2, 60) with optional OVER (PARTITION BY key)
Snapshot Groups events with the same timestamp No GROUP BY System.Timestamp()

Tumbling windows include their end boundary and exclude the start by default (an optional offset changes this). For session windows, the maximum duration is checked at intervals equal to the maximum duration, so an actual session can last up to twice that value. Windows() computes several window definitions in one GROUP BY.

SELECT
    System.Timestamp() AS WindowEnd,
    deviceId,
    AVG(temperature) AS AvgTemp
INTO [DeviceAverages]
FROM [DeviceInput] TIMESTAMP BY eventTime
GROUP BY deviceId, HoppingWindow(minute, 10, 1)
HAVING AVG(temperature) > 75

This emits, every minute, the 10-minute average per device using event time, keeping only devices averaging over 75; each event contributes to ten overlapping windows.

Common trap: Picking a hopping window when every event must be counted exactly once - hopping windows overlap whenever the hop is shorter than the size, so events are counted in several results; use a tumbling window (or a hop equal to the size).

Common trap: Assuming a session window can never exceed its maximum duration - the maximum is checked at intervals equal to that duration, so a session can last up to twice the configured maximum.

Get the whole book

This note is one section of Ultra Transcenders DP-700: Implementing Data Engineering Solutions Using Microsoft Fabric, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in December 2026, in Kindle and paperback editions.

About the book · DP-700 terms in the glossary · All DP-700 study notes

More DP-700 study notes