How the five eventstream window types group events in time, how they overlap and how to write them in the SQL operator.
From Ultra Transcenders DP-700 by Tony Rough (coming December 2026)
Windows group events by time so you can aggregate them. Eventstreams inherit Azure Stream Analytics windowing, so the five classic window types apply.
Eventstream windows appear in the no-code Group by operator (time window plus grouping fields; Learn’s migration guide lists tumbling, hopping and sliding patterns there) and in full in the SQL operator, where a window function goes in the GROUP BY clause. Every window emits its result at the end of the window, timestamped with the window end (System.Timestamp()), and windows align to the zeroth hour. A window’s maximum size is seven days.
| Window | Definition | Overlap | Syntax (SQL operator) |
|---|---|---|---|
| Tumbling | Fixed-size, contiguous, non-overlapping intervals | None: each event is in exactly one window | TumblingWindow(minute, 5) |
| Hopping | Fixed size that hops forward by a set period | Yes when hop is smaller than size; hop equal to size is a tumbling window | HoppingWindow(minute, 10, 5) |
| Sliding | Emits only when an event enters or leaves the window | Yes; every window contains at least one event | SlidingWindow(minute, 10) |
| Session | Starts at the first event, extends while events arrive within the timeout, closes at the timeout or maximum duration | No; gaps with no data are filtered out | SessionWindow(minute, 2, 60) with optional OVER (PARTITION BY key) |
| Snapshot | Groups events with the same timestamp | No | GROUP BY System.Timestamp() |
Tumbling windows include their end boundary and exclude the start by default (an optional offset changes this). For session windows, the maximum duration is checked at intervals equal to the maximum duration, so an actual session can last up to twice that value. Windows() computes several window definitions in one GROUP BY.
SELECT
System.Timestamp() AS WindowEnd,
deviceId,
AVG(temperature) AS AvgTemp
INTO [DeviceAverages]
FROM [DeviceInput] TIMESTAMP BY eventTime
GROUP BY deviceId, HoppingWindow(minute, 10, 1)
HAVING AVG(temperature) > 75This emits, every minute, the 10-minute average per device using event time, keeping only devices averaging over 75; each event contributes to ten overlapping windows.
Common trap: Picking a hopping window when every event must be counted exactly once - hopping windows overlap whenever the hop is shorter than the size, so events are counted in several results; use a tumbling window (or a hop equal to the size).
Common trap: Assuming a session window can never exceed its maximum duration - the maximum is checked at intervals equal to that duration, so a session can last up to twice the configured maximum.
This note is one section of Ultra Transcenders DP-700: Implementing Data Engineering Solutions Using Microsoft Fabric, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in December 2026, in Kindle and paperback editions.
About the book · DP-700 terms in the glossary · All DP-700 study notes
How purpose, skills and coding level decide between Dataflow Gen2, a pipeline and a notebook, and where Copy job and Apache Airflow jobs fit.
How authoring style, output, storage, state and latency decide between eventstreams, Spark structured streaming and eventhouses.
When a KQL database should ingest data, query it through a standard OneLake shortcut, or accelerate the shortcut, and what each costs.
When to reload everything or only changes, and which change-detection method catches inserts, updates and deletes.
How starter, custom, capacity and custom live pools differ in node sizes, start-up time, sizing against the capacity and job admission.
The default, email, random and partial masks, the permissions that add or bypass them, and why masking alone doesn't stop inference.
How skills, data location and transformation type decide between Dataflow Gen2, Spark notebooks, KQL update policies and warehouse T-SQL.