Table in Log Analytics where entries from Windows event logs are kept.
Also called table.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Event in context, with comparison tables and the common traps.
Terms in this definition
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
Related terms
- AADRiskyUsers
A Log Analytics table listing the users that Microsoft Entra ID Protection flags as risky, with each user's risk level and state. It is populated once you export the RiskyUsers category through diagnostic settings.
- AADSignInEventsBeta
An advanced hunting table holding both interactive and non-interactive Microsoft Entra sign-ins, available with Entra ID P2. From 19 October 2026 EntraIdSignInEvents takes over from it, and existing queries move across automatically.
- AADUserRiskEvents
A Log Analytics table recording the user risk detections raised by Microsoft Entra ID Protection. Data arrives once the UserRiskEvents category is exported through diagnostic settings.
- ABAC policy
Governed tags drive this kind of Unity Catalog rule: when a table or column has tags that satisfy its
WHENandMATCH COLUMNSconditions, a row filter or column mask UDF is put on it automatically. Policies are written withCREATE POLICYand can sit on a metastore, catalog, schema or table. - Activity log alert
Alert rule without state that triggers on a matching Activity log event, deleting a management lock for instance. A scope, a condition and an action group are required; a Log Analytics workspace is not.
- Adaptive target file size
A Spark setting in Fabric that chooses the target file size for each Delta table based on how big the table is, starting at 128 MB for small tables and rising towards 1 GB for very large ones, and reconsiders the choice every time
OPTIMIZEruns. It is enabled by default in Runtime 2.0 and removes the need to tune the olderdelta.targetFileSizeproperty by hand. - ADDCOLUMNS
A DAX function that takes a table and hands it back with extra computed columns appended, working out each new expression row by row while keeping every existing column.
- Advanced data parsing
Structure-aware document processing: it applies OCR to scanned pages, joins tables spanning pages, recovers headers and produces chunks tagged with heading, page and table metadata, in contrast to fixed-size or page-by-page chunking.