A KQL statement inside a data collection rule that drops or reshapes incoming records before storage. Selecting which Windows events the agent gathers is done with XPath instead.
Also called transformation.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains DCR transformation in context, with comparison tables and the common traps.
Terms in this definition
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- Data collection rule
Rule in Azure Monitor specifying what the Azure Monitor Agent or Logs Ingestion API gathers (XPath event filters, for example), any transformation applied, and the destination.
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - Agent
A specialised form of Microsoft Copilot set up for one particular job, pairing instructions with knowledge and skills. You can create one in Copilot Studio, SharePoint or Agent Builder, and administrators control them from the Microsoft 365 admin center.
- XPath
Expressions such as Security!*[System[(EventID=4648)]], placed in a DCR's xPathQueries, that decide which Windows events AMA gathers. Each portal box takes 20 at most, and a DCR is limited to 100.
Related terms
- Column from examples
Type a few sample results and Power Query works out the transformation that produces them, looking at the first 100 rows, then adds it as a new column.
- Navigator
Once Power Query connects to a source, this window pops up listing what the source contains, with a preview, so you can select items and then either load them straight away or open them for transformation.
- series roll-up
How often data points get combined, in a VCF Operations view, prior to calculating the transformation.