Azure Data Explorer is Microsoft's KQL-based service for analysing large volumes of data. Log Analytics can reach it through the adx() function, though queries and jobs in the Sentinel data lake cannot.
Also called Azure Data Explorer.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains ADX in context, with comparison tables and the common traps.
Terms in this definition
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
- Data lake
Holds files of every kind, structured, semi-structured or unstructured, usually spread over a distributed file system, and lets engines like Spark apply a schema when reading. In Azure this is Data Lake Storage: Blob Storage with a hierarchical namespace enabled.
Related terms
- Database shortcut
Read-only by design, this eventhouse KQL database references another KQL or Azure Data Explorer database and keeps in sync with it, with no ingestion of its own. You can adjust its principals, permissions and caching policy, but nothing else.
- Database watcher
Dashboards and alerts sit on top of this preview Azure service, which collects detailed performance and workload data from managed instances, elastic pools and Azure SQL databases and keeps it in Real-Time Analytics or Azure Data Explorer.
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- Time Series Insights
A now-retired Azure service for analysing IoT time-series data; Azure Data Explorer replaces it.